nanog mailing list archives
Re: Sobig.f surprise attack today
From: Damian Gerow <damian () sentex net>
Date: Thu, 28 Aug 2003 16:32:31 -0400
Thus spake Petri Helenius (pete () he iki fi) [28/08/03 16:23]:
I dont think this would work too well. The users who are infected often think something is wrong because their connection and computer are not working quite right. So they disconnect / reconnect / reboot so they burn through quite a few dynamic IP addresses along the way.This is an artifact of ISP?s wanting to have static IP?s as an add-on premium service so they provide short lease times and change IP as often as it?s feasible without interrupting service unneccessarily.
Or potentially an artifact of wanting more IP space from ARIN, as opposed to assigning a static IP to every user we have, even the ones that are only connected for about an hour a month. But hey, that's just a minor detail.
Current thread:
- Re: Sobig.f surprise attack today, (continued)
- Re: Sobig.f surprise attack today Owen DeLong (Aug 22)
- Re: Sobig.f surprise attack today Jay Hennigan (Aug 22)
- Message not available
- Re: Sobig.f surprise attack today Owen DeLong (Aug 22)
- Re: Sobig.f surprise attack today Doug Barton (Aug 22)
- Re: Sobig.f surprise attack today Owen DeLong (Aug 28)
- Re: Sobig.f surprise attack today Dan Hollis (Aug 28)
- Re: Sobig.f surprise attack today Mike Tancsa (Aug 28)
- Re: Sobig.f surprise attack today Petri Helenius (Aug 28)
- Re: Sobig.f surprise attack today Mike Tancsa (Aug 28)
- Re: Sobig.f surprise attack today Patrick Muldoon (Aug 28)
- Re: Sobig.f surprise attack today Damian Gerow (Aug 28)
- Re: Sobig.f surprise attack today Petri Helenius (Aug 28)
- Re: Sobig.f surprise attack today Mike Tancsa (Aug 28)
- Re: Sobig.f surprise attack today Owen DeLong (Aug 22)
- Re: Sobig.f surprise attack today steve uurtamo (Aug 22)