DDOS: Mstream Handler To Client on TCP/12754

This signature detects the command string ">" in a TCP packet to port 12754 with the ACK and PUSH flags set. This can indicate that an Mstream handler is attempting to communicate with an Mstream client. Attackers can use Mstream, a denial-of-service (DoS) attack tool, to flood IP addresses with TCP ACK packets from forged source addresses.

Short Name
SCAN:MISC:MSTREAM-REP-12754
Severity
Info
Recommended
False
Recommended Action
None
Category
SCAN
Keywords
CVE-2000-0138 Client Handler Mstream TCP/12754 To on
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/12754
False Positive
Rarely
CVSS Score

5.0

Found a potential security threat?