[67797] in North American Network Operators' Group
Re: BL of Compromised Hosts?
daemon@ATHENA.MIT.EDU (Daniel Concepcion)
Sun Feb 22 13:22:48 2004
From: Daniel Concepcion <dani@danielcp.net>
Reply-To: dani@danielcp.net
To: Deepak Jain <deepak@ai.net>
Date: Sun, 22 Feb 2004 19:20:25 +0100
Cc: nanog@merit.edu
In-Reply-To: <4038D4F6.9050200@ai.net>
Errors-To: owner-nanog-outgoing@merit.edu
Hi Deepak,
Check
http://www.cymru.com/BGP/bogon-rs.html
They are doing a good job in this issue.
Regards,
Daniel
On Sunday 22 February 2004 17:12, Deepak Jain wrote:
> Would anyone be interested in receiving a text or BGP feed of IPs of
> hosts known/suspected to be compromised and used as parts of DDOS
> attacks? Would anyone be interested in contributing their BGP views?
>
> We have (and I'm sure we're not isolated) been seeing attacks from
> several thousand/tens of thousands of unique hosts generated >2Gb/s,
>
> >1Mpps attacks.
>
> I am not necessarily suggesting that providers use this list to
> blackhole at their edge, but its certainly a good candidate for that. It
> could alternatively be used by access providers to notify their
> customers or filter on their customers. I am sure it would also be a
> good list to use to deny traffic to SMTP servers from/to.
>
> I'm not really an activist, so if there is real interest, I will be glad
> to set it up and contribute our own significant list of sources.
>
> If this is already done and I don't have a good set of skills with
> Google, please let me know.
>
> Thanks in advance,
>
> Deepak Jain
> AiNET