Results 1 to 5 of 5

Thread: TCP flag values

  1. #1

    TCP flag values

    Is there any source where tcp flag values are listed.
    I'm dealing woth snort rules and I think it would be nice to know what A+ and other TCP values are......

  2. #2

    Re: TCP flag values


  3. #3

  4. #4

    Re: TCP flag values

    THanks guys. Those flags are quite familiar. The reason I'm asking this question is that I took a look at the rules that snort IDS processes and there is an entry in the rule that looks like this:
    (msg:"PORN free XXX"; content:"FREE XXX"; nocase; flags:A+; classtype:kickass-porn; sid:1310; rev:1

    Please notice the flags:A+; part - flags are TCP flags A+ looks like a value...I was thinking that there are a bunch of tcp flag values that I'm not aware of, like A+
    Do you have any idea what the A+ is?
    thx.

  5. #5

    Re: TCP flag values

    The A means Ack, and the + means match on all specified flags plus any others. *You can find out more here
    http://www.snort.org/docs/writing_ru...#tth_sEc2.3.13

Similar Threads

  1. TCP packet with RST flag not carrying DSCP
    By Solace in forum Linux - Hardware, Networking & Security
    Replies: 0
    Last Post: 10-08-2009, 05:17 PM
  2. Program to show RGB values?
    By Compunuts in forum Windows - General Topics
    Replies: 6
    Last Post: 06-06-2006, 04:32 AM
  3. Exporting Documentation Tagged Values From Visio
    By KIMCOVoyageurs in forum Windows - General Topics
    Replies: 0
    Last Post: 08-03-2005, 02:52 PM
  4. HELP!!! can't boot: inode x has image flag set
    By Blaqb0x in forum Linux - General Topics
    Replies: 3
    Last Post: 03-01-2003, 09:42 PM
  5. PET: GCC compile flag fun (draft)
    By in forum Linux - General Topics
    Replies: 2
    Last Post: 06-25-2002, 02:14 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •