Paul Johnston <[EMAIL PROTECTED]> writes:

> I have accidentally DoSed stateful firewalls with nmap. If you
> originate the scan behind it, then the firewall needs a state table
> entry for each port being scanned. When you do a 64k port scan, this
> tends to exceed what the fw was designed for.

Well, in my case, the firewall resisted to port scans but went mad
much later. I suspect this is a bug, not a mere saturation, because
the beast has *much* memory.

Reply via email to