nanog mailing list archives

Re: ICANN Targets DDoS Attacks


From: "Peter E. Fry" <pfry () swbell net>
Date: Tue, 29 Oct 2002 22:49:15 -0600


On 29 Oct 2002 at 20:51, Brett Frankenberger wrote:

  Brett!  Long time, no hear, now that the Nortel/Bay newsgroup has 
pretty much wound down.  Like Usenet in general.

Addressing just the issue of how traceroute works, I'll point out that
(a) Most or all flavors of traceroute distributed by Microsoft use ICMP
ECHO instead of UDP for the outbound packets [...]

   ...And I rather like that method.  It's sad, but I'll not allow 
random high-port UDP to my stations.

FWIW, I don't think rate limiting ICMP is likely to have a negative
impact.  I also don't think it's a good idea, though -- it might help
to identify or prevent some problems in the short term, but in the long
run, it's a race we can't win [...]

  Hmmm.  Agreed.

Peter E. Fry


Current thread: