# Few questions...

**URL:** <https://community.zeek.org/t/few-questions/268>\
**Category:** Zeek\
**Created:** [July 25, 2002, 11:03pm UTC](https://community.zeek.org/t/few-questions/268 "2002-07-25T23:03:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [July 25, 2002, 11:03pm UTC](https://community.zeek.org/t/few-questions/268/1 "2002-07-25T23:03:37Z")

</div>

> I could not find any bro mailing list archive.

(it's available as a single flat file [:-(] by sending "get bro archive"  
in the body of a message mailed to majordomo@lbl.gov)

> Does bro detects illegal TCP acknowledgements and  
> retransmissions which i could not see using ordinary  
> dump utility?

Depends what you mean by "illegal". It detects acknowledgments above  
sequence holes, and inconsistent TCP retransmission. Unfortunately, when  
looking at a large volume of traffic, these show up due to various things  
being broken (as mentioned in the Bro paper), so their presence isn't  
a useful indicator of an attack.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/few-questions/268/2 "2022-05-06T15:36:33Z")

</div>


