[194321] in North American Network Operators' Group
Re: did facebook just DoS me?
daemon@ATHENA.MIT.EDU (Christopher Morrow)
Tue Apr 4 20:58:46 2017
X-Original-To: nanog@nanog.org
In-Reply-To: <CAPbn28nNCdeZb-wdVCECdg_idvu2v6eX7A3NngnYZYJkij0v-A@mail.gmail.com>
From: Christopher Morrow <morrowc.lists@gmail.com>
Date: Tue, 4 Apr 2017 18:58:43 -0600
To: Kurt Kraut <listas@kurtkraut.net>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org
On Tue, Apr 4, 2017 at 6:47 PM, Kurt Kraut <listas@kurtkraut.net> wrote:
>
> I perform some PCAPs I many IP addresses belonged to Facebook. At first I
> thought: - 'Clever attacker. He guesses I could not be as severe as I am to
> regular UDP traffic if the origin was Facebook and he deliberately spoofed
> their IP address.'
>
> But one of my collegues quickly realized the incoming MAC ADDRESS was the
> actual Facebook router we have a peering at a internet exchange. So indeed
> the traffic came from their network.
>
one wonders if this is the new (ish?) Streaming thingy they launched?