nanog mailing list archives
Re: UDP Amplification DDoS - Help!
From: "Roland Dobbins" <rdobbins () arbor net>
Date: Tue, 09 Feb 2016 09:54:10 +0700
On 9 Feb 2016, at 9:50, mike.lyon () gmail com wrote:
Sounds like there is a compromised host downstream of the 1G that is reporting back it's source IP and that is why changing the IP doesn't help.
It's much more likely that the attacker is just following the DNS changes.
----------------------------------- Roland Dobbins <rdobbins () arbor net>
Current thread:
- UDP Amplification DDoS - Help! Mitch Dyer (Feb 08)
- Re: UDP Amplification DDoS - Help! mike . lyon (Feb 08)
- Re: UDP Amplification DDoS - Help! Roland Dobbins (Feb 08)
- Re: UDP Amplification DDoS - Help! Faisal Imtiaz (Feb 08)
- Re: UDP Amplification DDoS - Help! Andrew Kirch (Feb 08)
- Re: UDP Amplification DDoS - Help! Roland Dobbins (Feb 08)
- Re: UDP Amplification DDoS - Help! Tin, James (Feb 08)
- RE: UDP Amplification DDoS - Help! Peter Kranz (Feb 08)
- Re: UDP Amplification DDoS - Help! Rubens Kuhl (Feb 08)
- Re: UDP Amplification DDoS - Help! Karsten Elfenbein (Feb 09)
- Re: UDP Amplification DDoS - Help! mike . lyon (Feb 08)