Re: UDP flood DDoS attack with spoofed IP addresses
On Fri, Dec 07, 2007 at 05:52:47PM +0800, Thomas Goirand wrote:
> Hi, > > Has any of you had to deal with this type of attack? What is the way to > get the real IPs and finally found out where is the bootnet and destroy it? >
Getting the source IPs can be tricky. If you have a good relationship
with your upstream ISP, they can probably help out. Destroying the
botnet is probably best left to law enforcement.
Regards,
-Roberto
--
Roberto C. Sánchez
http://people.connexer.com/~robertohttp://www.connexer.com
--
To UNSUBSCRIBE, email to debian-isp-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Fri Dec 7 07:01:54 2007
This archive was generated by hypermail 2.1.8
: Wed Mar 19 2008 - 06:51:35 EDT
|