[129340] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: just seen my first IPv6 network abuse scan, is this the start

daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Fri Sep 3 07:49:46 2010

From: "Dobbins, Roland" <rdobbins@arbor.net>
To: NANOG list <nanog@nanog.org>
Date: Fri, 3 Sep 2010 11:49:38 +0000
In-Reply-To: <4C80DF58.30000@de-cix.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Sep 3, 2010, at 6:43 PM, Matthias Flittner wrote:

> sounds for me as an typicall IPv6 DoS attack. (see RFC3756)


GMTA.  Suggest checking to see if the targets have in fact been compromised=
 (perhaps co-opted as botnet C&Cs, malware drop sites, et. al.?), and are b=
eing targeted by a rival gang.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>

 	       Sell your computer and buy a guitar.






home help back first fref pref prev next nref lref last post