nanog mailing list archives
Re: Odd DDoS, anyone else seen this?
From: <bdragon () gweep net>
Date: Fri, 29 Nov 2002 18:35:39 -0500 (EST)
Looked just like a regular SYN flood to the target IP. Not sure why they picked source addresses that were so obviously bogus though. Can anyone think of a reason why this sort of traffic should be routed at all? Does anyone actually drop hosts on to addresses ending in x.x.x.0?
x.x.0.0 is a valid ip address for networks with bit lengths of 0 through 15. And yes, folks do use /32 and /31 addresses which end in .0.
Rich
Current thread:
- Odd DDoS, anyone else seen this? Stephen J. Wilcox (Nov 25)
- Re: Odd DDoS, anyone else seen this? variable (Nov 25)
- Re: Odd DDoS, anyone else seen this? Stephen J. Wilcox (Nov 25)
- Re: Odd DDoS, anyone else seen this? variable (Nov 25)
- Re: Odd DDoS, anyone else seen this? Valdis . Kletnieks (Nov 25)
- Re: Odd DDoS, anyone else seen this? Stephen J. Wilcox (Nov 25)
- Re: Odd DDoS, anyone else seen this? Christopher L. Morrow (Nov 25)
- Re: Odd DDoS, anyone else seen this? jlewis (Nov 25)
- Re: Odd DDoS, anyone else seen this? Joel Jaeggli (Nov 25)
- Message not available
- Re: Odd DDoS, anyone else seen this? Joe Provo (Nov 26)
- Re: Odd DDoS, anyone else seen this? variable (Nov 25)
- <Possible follow-ups>
- Re: Odd DDoS, anyone else seen this? variable (Nov 25)
- Re: Odd DDoS, anyone else seen this? Stephen J. Wilcox (Nov 25)