home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
MacWorld 2000 January
/
Macworld (2000-01).dmg
/
Updaters
/
NetMinder® Ethernet 4.2 Patch
/
Replace Packet Inference ƒ
/
Packet Inference Read Me
next >
Wrap
Text File
|
1999-10-06
|
2KB
|
67 lines
Packet Inference Read Me
Description: The accompanying file is an update to NetMinder Ethernet's
Packet Inference rules module. This file needs to be placed in the
Packet Inference folder.
Packet Inference 4.3 -- Release Notes
This version adds a new rule for detecting Land (land.c) attacks.
The rule looks for IP/TCP SYN packets with the source and destination
IP addresses the same and the source and destination TCP ports the
same. While this rule does not guaranty that an attack is occurring,
you should check the IP addresses printed by Packet Inference as it
is highly unusual that an IP device sends SYN packets to itself.
The Land attack rule is set to High priority.
Packet Inference 4.2 -- Release Notes
This version adds a new rule for detecting duplicate AppleTalk
addresses. Note: this rule is not foolproof -- it *may* detect
a duplicate AppleTalk address when, in fact, there is none. In
particular, if the Ethernet segment to which NetMinder Ethernet
is directly connected has more than one AppleTalk router, this
rule may indicate duplicate AppleTalk addresses.
If your Packet Inference is reporting many extraneous duplicate
AppleTalk addresses, set the Reporting Level options to Medium
or High by clicking the Options button in the Packet Inference
window. The duplicate AppleTalk addresses rule is set to Low
priority.
Packet Inference 4.1 -- Release Notes
This version adds a new rule for detecting Ping of Death attacks.
The rule looks for IP/ICMP echo request packets over 1000 bytes in
length and having the More Fragments flag set in the IP header.
While this rule does not guaranty that an attack is occurring, you
should check the source and destination IP addresses printed by
Packet Inference, as fragmented ICMP echo packets are quite uncommon.
If your Packet Inference is reporting many such Ping of Death packets,
because these packets are commonly and normally seen on your network,
set the Reporting Level options to Medium or High by clicking the
Options button in the Packet Inference window. The Ping of Death rule
is set to Low priority.
This version also sets the New LAT node rule to be of Low priority.
Neon Software, Inc.
3685 Mt. Diablo Blvd. Suite 253
Lafayette, CA 94549
Tel: (925) 283-9771, (800) 334-NEON
Fax: (925) 283-6507
WWW: http://www.neon.com
Information: info@neon.com
Technical Support: support@neon.com