[prev in list] [next in list] [prev in thread] [next in thread] 

List:       nanog
Subject:    Re: Odd DDoS, anyone else seen this?
From:       <bdragon () gweep ! net>
Date:       2002-11-29 23:35:39
[Download RAW message or body]


> Looked just like a regular SYN flood to the target IP.  Not sure why they
> picked source addresses that were so obviously bogus though.
> 
> Can anyone think of a reason why this sort of traffic should be routed at 
> all?  Does anyone actually drop hosts on to addresses ending in x.x.x.0?

x.x.0.0 is a valid ip address for networks with bit lengths of 0 through 15.
And yes, folks do use /32 and /31 addresses which end in .0.

> Rich

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic