nanog mailing list archives
Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks)
From: Damian Menscher via NANOG <nanog () nanog org>
Date: Tue, 27 Aug 2019 16:23:19 -0700
On Wed, Aug 21, 2019 at 3:21 PM Töma Gavrichenkov <ximaera () gmail com> wrote:
On Thu, Aug 22, 2019 at 12:17 AM Damian Menscher <damian () google com> wrote:Some additional questions, if you're able to answer them (off-list isfine if there are things that can't be shared broadly):- Was the attack referred to law enforcement?It is being referred to now. This would most probably get going under the jurisdiction of the Netherlands.
Deeper analysis and discussion indicates there were several victims: we saw brief attacks targeting some of our cloud customers with syn-ack peaks above 125 Mpps; another provider reported seeing 275Mpps sustained. So presumably there are a few law enforcement investigations under way, in various jurisdictions.
- Were any transit providers asked to trace thesource of the spoofing to either stop the attack or facilitate the law enforcement investigation?No.... tracing the source was not deemed a high priority task.
Fair enough. I just didn't want to duplicate effort. The source of the spoofing has been traced. The responsible hosting provider has kicked off their problem customer, and is exploring the necessary filtering to prevent a recurrence. If anyone sees more of this style of attack please send up a flare so the community knows to track down the new source. Damian
Current thread:
- Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Töma Gavrichenkov (Aug 21)
- Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Damian Menscher via NANOG (Aug 21)
- Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Töma Gavrichenkov (Aug 21)
- Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Damian Menscher via NANOG (Aug 27)
- Re: Reflection DDoS last week Denys Fedoryshchenko (Aug 28)
- Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Töma Gavrichenkov (Aug 21)
- Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Damian Menscher via NANOG (Aug 21)
- Re: Reflection DDoS last week (was: syn flood attacks from NL-based netblocks) Amir Herzberg (Aug 21)
- Re: Reflection DDoS last week Denys Fedoryshchenko (Aug 24)