[60501] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: The impending DDoS storm

daemon@ATHENA.MIT.EDU (Lloyd Taylor)
Wed Aug 13 12:26:41 2003

Date: Wed, 13 Aug 2003 09:25:52 -0700 (PDT)
From: Lloyd Taylor <ltaylor@keynote.com>
To: Jack Bates <jbates@brightok.net>
Cc: nanog@merit.edu
In-Reply-To: <3F3A62E5.7060008@brightok.net>
Errors-To: owner-nanog-outgoing@merit.edu


Does anyone have any notion of what the Blaster worm will do if the
DNS lookup for "windowsupdate.com" returns NXDOMAIN?  If it handles this
case by not sending any micreant love, might that not be the best way
to mitigate the potential damage?

--Lloyd

On Wed, 13 Aug 2003, Jack Bates wrote:

> Date: Wed, 13 Aug 2003 11:10:13 -0500
> From: Jack Bates <jbates@brightok.net>
> To: Jason Frisvold <friz@corp.ptd.net>
> Cc: "Ingevaldson, Dan (ISS Atlanta)" <dsi@iss.net>,
>      Stephen J. Wilcox <steve@telecomplete.co.uk>, nanog@merit.edu
> Subject: Re: The impending DDoS storm
> 
> 
> On Wed, 2003-08-13 at 10:55, Ingevaldson, Dan (ISS Atlanta) wrote:
> >-Does one DNS lookup on "windowsupdate.com" and then uses the IP
> 
> No, I wouldn't dream of setting windowsupdate.com to 127.0.0.1. Who in 
> their right mind would do that?
> 
> -Jack
> 

-- 


home help back first fref pref prev next nref lref last post