[61255] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: relays.osirusoft.com

daemon@ATHENA.MIT.EDU (Matthew Sullivan)
Tue Aug 26 19:46:27 2003

Date: Wed, 27 Aug 2003 09:45:37 +1000
From: Matthew Sullivan <matthew@sorbs.net>
To: George William Herbert <gherbert@retro.com>, nanog@merit.edu
In-Reply-To: <200308262307.h7QN7XN01777@gw.retro.com>
Errors-To: owner-nanog-outgoing@merit.edu


George William Herbert wrote:

>Yes, this is due to a massive DDOS.  At least three
>of the spamfilter BLs have been so attacked this week.
>
>Some of the networks represented here have not been
>as timely about helping the BL providers with the
>DDOSes as they could be.  Please keep in mind that
>without dynamic BLs anti-spam folks will fall back
>to sending out static block maps, which getting your
>IP space out of will be difficult if not impossible.
>
>IT IS VERY MUCH IN NETWORK OPERATORS
>BEST INTEREST THAT THIS NOT HAPPEN.
>
>Please take what measures are necessary to help
>ensure that your customers are not intentionally
>or neglegently DDOSing the BLs.
>  
>
Well said George,

I have been one of the recepients of the DDoS attacks.  If people see 
non DNS UDP traffic or non Type 3 ICMP traffic aimed at 203.15.51.32/27 
it is likely DDoS traffic.  Currently I still have at least one IP in 
that range Null Routed by upstreams.

SORBS may have to implement a subscription model soon to fund more hosts 
around the world if the DDoS's continue,  I am desperately trying to 
avoid it, should it become nessessary it will be for the +50k 
queries/day users out there.  The point is SORBS is funded soley by 
myself and through hosting dontations - I have 5 public secondaries 
donated currently, and I cannot afford, personally, any DDoS proofing 
other than that I have now.  I know of at least 3 other DNSbls that are 
experiencing DDoS issues, and one DNSbl operator that is scared stiff of 
DDoS.

Yours

Mat

Note: If anyone wants to talk about SORBS, public secondaries, 
donations, policy etc... this is not the forum, please contact me off list.




home help back first fref pref prev next nref lref last post