SCAN: Cybercop UDP Bomb
This signature detects attempts to scan the system using CyberCop Scanner. Attackers can be attempting to determine if the system is vulnerable to a UDP bomb denial-of-service (DoS) attack (a UDP port is flooded with ECHO and CHARGEN packets by connecting a host ECHO service to a local or remote CHARGEN service).
Extended Description
CyberCop Scanner can be used for a UDP Bomb attack. This signature detects such an attempt. A successful attack creates a denial of service condition.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
5.0