[80046] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: New worm?

daemon@ATHENA.MIT.EDU (Christopher L. Morrow)
Fri Apr 22 01:27:15 2005

Date: Fri, 22 Apr 2005 05:26:50 +0000 (GMT)
From: "Christopher L. Morrow" <christopher.morrow@mci.com>
In-reply-to: <897ad8eaa22d48ad30e7ede9e59e8455@gizmopartners.com>
To: Chris Boyd <cboyd@gizmopartners.com>
Cc: nanog@merit.edu
Errors-To: owner-nanog@merit.edu



On Fri, 22 Apr 2005, Chris Boyd wrote:

>
>
> On Apr 22, 2005, at 12:13 AM, Christopher L. Morrow wrote:
> > do you atleast have info about the packet
> > types/destinations/anything-useful ?
> >
>
> Netflow is showing a lot of 1500 byte packets, but many different
> destinations.  It looks similar to gnutella traffic.  Maybe just a lot
> files to share and our rate shapers are broken.

probably also it says ports and protocol?

home help back first fref pref prev next nref lref last post