nanog mailing list archives

Re: Odd DDoS, anyone else seen this?


From: <bdragon () gweep net>
Date: Fri, 29 Nov 2002 18:35:39 -0500 (EST)


Looked just like a regular SYN flood to the target IP.  Not sure why they
picked source addresses that were so obviously bogus though.

Can anyone think of a reason why this sort of traffic should be routed at 
all?  Does anyone actually drop hosts on to addresses ending in x.x.x.0?

x.x.0.0 is a valid ip address for networks with bit lengths of 0 through 15.
And yes, folks do use /32 and /31 addresses which end in .0.

Rich


Current thread: