[129343] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: just seen my first IPv6 network abuse scan, is this the start

daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Fri Sep 3 08:18:51 2010

From: "Dobbins, Roland" <rdobbins@arbor.net>
To: NANOG list <nanog@nanog.org>
Date: Fri, 3 Sep 2010 12:12:42 +0000
In-Reply-To: <AANLkTikLa+15SQwz9eEnU1iaUbyHMgMccJDtuCNVHkx8@mail.gmail.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Sep 3, 2010, at 7:02 PM, Igor Ybema wrote:

>  The only traffic I saw on the subnet was normal/valid NA lookups from th=
e router towards an
> increasing IPv6-address (starting with ::1, then ::2 etc).


This could be a deliberately-induced DDoS due to the annoying ND stuff in I=
Pv6, or just an ICMP sweep.  Did it seem to concentrate on certain ranges, =
were the target addresses progressive, et. al.?

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>

 	       Sell your computer and buy a guitar.






home help back first fref pref prev next nref lref last post