Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: unidentified DOS "bad traffic"

From: Alain Fauconnet <alain(at)cscoms.net>
Date: Thu Mar 13 2003 - 22:55:31 EST

Hello,

On Thu, Mar 13, 2003 at 03:53:59PM -0600, DY wrote:
>
> Twice in the past week I have experienced a severe DOS condition on my

Looks very close to something I've experienced recently as well. My research has pointed me to the following places:

http://lists.insecure.org/lists/incidents/2002/May/0026.html http://cert.uni-stuttgart.de/archive/incidents/2002/05/msg00026.html

This is about a DoS and warez distribution IRC BOT. It uses IP protocol 255 also.

> "bad traffic," resolves (reverse) to irc-m.icq.aol.com.

Same for me! also 2 other IPs in cable.midspring.com and mdweb1.c.mad.interhost.com (Spain)

Do you need help?X

> 4) There was so much of this traffic that it shut my network down. My
> main router (Cisco) reported no appreciable CPU consumption during the
> attack. It just appears that the sheer volume of the [bad] packets choked
> everybody out.

Ditto.

Hope that helps,
_Alain_


<Pre>Lose another weekend managing your IDS? Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre> <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A> Received on Fri Mar 14 12:24:16 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:00 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library