Re: Scanning with reverse connections?
In article <[🔎] 3EDF9A06.firstname.lastname@example.org>
>I've noticed some strange traffic on our firewalls recently. Someone (Or
>multiple someones) are attempting to send tcp packets inbound to our
>network FROM well known ports (e.g. port 80)
Some firewalls that don't do proper connection tracking can be
bypassed that way. With a properly configured iptables firewall this
shouldn't be a problem. ipchains based firewalls are more likely to
fall victom to this trick.
Treat it the same as any other attempt to break into your systems.
Blars Blarson email@example.com
"Text is a way we cheat time." -- Patrick Nielsen Hayden