 hotmax join:2004-04-12 New York, NY | reply to MingusMoo
Re: MSSQL_NULL_PACKET_DOS intrusion attempts BTW just disregard the destination address. I use bittorent too, and I recognize those port ranges. In my case, I use 6881-6999, and such was the target port for the destination address in my log. I think NPF just picks a random/recently active destination as your target, either because it is confused from all the hammering, or it could not read the header in the packet that the program sent. Remember that if you see the dos alert in NPF, you can be sure that it never got there. |