[129343] in North American Network Operators' Group
Re: just seen my first IPv6 network abuse scan, is this the start
daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Fri Sep 3 08:18:51 2010
From: "Dobbins, Roland" <rdobbins@arbor.net>
To: NANOG list <nanog@nanog.org>
Date: Fri, 3 Sep 2010 12:12:42 +0000
In-Reply-To: <AANLkTikLa+15SQwz9eEnU1iaUbyHMgMccJDtuCNVHkx8@mail.gmail.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Sep 3, 2010, at 7:02 PM, Igor Ybema wrote:
> The only traffic I saw on the subnet was normal/valid NA lookups from th=
e router towards an
> increasing IPv6-address (starting with ::1, then ::2 etc).
This could be a deliberately-induced DDoS due to the annoying ND stuff in I=
Pv6, or just an ICMP sweep. Did it seem to concentrate on certain ranges, =
were the target addresses progressive, et. al.?
-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>
Sell your computer and buy a guitar.