|
|||||||||||
|
Re: unidentified DOS "bad traffic"
From: Alain Fauconnet <alain(at)cscoms.net>
Date: Thu Mar 13 2003 - 22:55:31 EST Hello,
On Thu, Mar 13, 2003 at 03:53:59PM -0600, DY wrote:
Looks very close to something I've experienced recently as well. My research has pointed me to the following places: http://lists.insecure.org/lists/incidents/2002/May/0026.html http://cert.uni-stuttgart.de/archive/incidents/2002/05/msg00026.html This is about a DoS and warez distribution IRC BOT. It uses IP protocol 255 also.
> "bad traffic," resolves (reverse) to irc-m.icq.aol.com.
Same for me! also 2 other IPs in cable.midspring.com and mdweb1.c.mad.interhost.com (Spain) > 4) There was so much of this traffic that it shut my network down. My
Ditto.
Hope that helps,
<Pre>Lose another weekend managing your IDS?
Take back your personal time.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:00 EDT |
||||||||||
|
|||||||||||