[187553] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: UDP Amplification DDoS - Help!

daemon@ATHENA.MIT.EDU (Roland Dobbins)
Mon Feb 8 21:54:17 2016

X-Original-To: nanog@nanog.org
From: "Roland Dobbins" <rdobbins@arbor.net>
To: "nanog@nanog.org" <nanog@nanog.org>
Date: Tue, 09 Feb 2016 09:54:10 +0700
In-Reply-To: <1B1BE967-20BE-4955-BFA5-7F6E053EE8FB@gmail.com>
Errors-To: nanog-bounces@nanog.org

On 9 Feb 2016, at 9:50, mike.lyon@gmail.com wrote:

> Sounds like there is a compromised host downstream of the 1G that is 
> reporting back it's source IP and that is why changing the IP doesn't 
> help.

It's much more likely that the attacker is just following the DNS 
changes.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>

home help back first fref pref prev next nref lref last post