[174123] in North American Network Operators' Group
Re: where to go to understand DDoS attack vector
daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Tue Aug 26 12:02:53 2014
X-Original-To: nanog@nanog.org
To: Roland Dobbins <rdobbins@arbor.net>
In-Reply-To: Your message of "Tue, 26 Aug 2014 18:57:27 +0700."
<1DDE300E-BAB9-4383-B87B-022F59AEA279@arbor.net>
From: Valdis.Kletnieks@vt.edu
Date: Tue, 26 Aug 2014 12:02:35 -0400
Cc: NANOG <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org
--==_Exmh_1409068955_1947P
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
On Tue, 26 Aug 2014 18:57:27 +0700, Roland Dobbins said:
>. The 'mailto:' bit is interesting; it might work sort of like SNMP reflection/amplificati
Nope. It's a red herring, somebody's MUA trying to get *far* too clever with
the fact that there's a literal "....@.8" in the ascii dump part of the packet.
Took me a few seconds to figure it out too, am a tad low on caffeine today. :)
--==_Exmh_1409068955_1947P
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: Exmh version 2.5 07/13/2001
iQIVAwUBU/yvmwdmEQWDXROgAQKvXw//Q1u8OdWBJTO3yv0P9jmNLR9c8G5zvymx
KZdWSsnmLrwoflvWcNeKbrIFdIja3Vav9rPfeXxL09/uxZTW3MPOkwyJiANrC6ZU
UTfrq39AwJo1MOGTqljNN+/rwl6n/Ay4FN5Fm9MWlwoHUqwvNV64j7UW0UrrPHiL
nE7WxkY6Qvgo1xqTZYP0BvYsWC+dI7o4HtvQ2S9n4b4Zi605LC+yolWFu+lwS1tG
RhBNeDZyxJqq/BFyGQbGMV8C4Q6g1BX+ftIWyp1ghLXjiOwRmEKOydla/ZoROMzn
FG5DDCgVL+Cz0ZqCQ9yKJOVNqUcdYezWof/3Ii4BOYwF5dZBQaDzrhB4JopjMlWv
Ng51rtGzywhkx2dsclh9Le8ApDMHLJOAWLF8uyTY3GnE90ClMlfmMAOuSziWn8O5
orchQthW3o0wGndeQuP32HJO9uapVHev0LDvtItFlpoJ04bbrnWBjm+Y5zD4h1aN
r1bo8bIt14710wluGPxqXFRiC7Gh+nLBXNePjMYfeFoS+bqOAxiLRsEjcKmfnGHM
ULUq8ElRgrFlU909HLA/aYjXXBIJ9BeA9BqhSjaHHrvGw8d6pCbnY5wxMQz6tVAM
kMmnef9+WkrQxG/MXJxrq2iZ04aWfAATPCs9KA8dLTBfegnsnC9GqCSeqsCwUwWx
TKVVmbadGEo=
=aDHD
-----END PGP SIGNATURE-----
--==_Exmh_1409068955_1947P--