Dave,
that is generally correct..though, this port has been exploited for host
fingerprinting.
piranha...
>From: Dave Horsfall <[EMAIL PROTECTED]>
>To: Firewalls List <[EMAIL PROTECTED]>
>Subject: Packets seen on a firewall [*]
>Date: Tue, 7 Nov 2000 18:06:44 +1100 (EST)
>
>I assume that source port 0 is completely invalid? Or is this a grossly
>misconfigured system?
>
>Nov 5 09:35:48 denied tcp 200.202.210.125(0) -> xxx.xxx.xxx.149(110), 1
>packet
>Nov 5 09:35:48 denied tcp 200.202.210.125(0) -> xxx.xxx.xxx.49(110), 1
>packet
>Nov 5 09:35:48 denied tcp 200.202.210.125(0) -> xxx.xxx.xxx.47(110), 1
>packet
>
>(A whole bunch of these, sent to this class C, from some place in Brazil)
>
>[*] Sounds like a good title for a paper :-)
>
>-- Dave
>
>-
>[To unsubscribe, send mail to [EMAIL PROTECTED] with
>"unsubscribe firewalls" in the body of the message.]
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.
Share information about yourself, create your own public profile at
http://profiles.msn.com.
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]