[39528] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: DDoS attacks

daemon@ATHENA.MIT.EDU (Rafi Sadowsky)
Thu Jul 12 20:09:29 2001

Date: Fri, 13 Jul 2001 03:08:55 +0300 (IDT)
From: Rafi Sadowsky <rafi-nanog@meron.openu.ac.il>
Reply-To: <nanog@merit.edu>
To: <up@3.am>
Cc: <nanog@merit.edu>
In-Reply-To: <Pine.BSF.4.10.10107121556270.58770-100000@richard2.pil.net>
Message-ID: <Pine.GSO.4.31.0107130256530.970-100000@meron.openu.ac.il>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Errors-To: owner-nanog-outgoing@merit.edu




On Thu, 12 Jul 2001 up@3.am wrote:

[deleted]
>
> On Thu, 12 Jul 2001, Alexei Roudnev wrote:
>
> > One important notice - most of this kiddies are not from USA.

 How exactly did you get to this conclusion ??

 The smarter script kiddies can crack systems in a few countries and use a
few hops to get the place they installed the zombie master
for example:

 <cracker> -> <Romania> -> <china> -> <Poland(DDoS master>

Good luck to you tracing the attack to the cracker ;-)


-	Rafi

-- 
Rafi Sadowsky                                   rafi@cert.ac.il
 Network Operations Center  |VoiceMail: +972-3-646-0592   FAX: +972-3-646-0454
  ILAN - IUCC -I2(Israel)   |    FIRST-REP for ILAN-CERT(CERT@CERT.AC.IL)
(Israeli Academic Network)  |   (PGP key -> )  http://telem.openu.ac.il/~rafi



> >
> > ----- Original Message -----
> > >
> > > > I can't help but believe that if even 20% of them
> > > > were caught and had to spend just a little time (even hours) with the
> > > > cops, and had their peecees confiscated, you'd not be seeing
> > > > nearly the problems we are now.
>
> James Smallacombe		      PlantageNet, Inc. CEO and Janitor
> up@3.am							    http://3.am
> =========================================================================
>
>




home help back first fref pref prev next nref lref last post