At 6:52 AM -0500 11/25/03, James M. Ray wrote:

Anyway, the important point is that it's hard to fight because it's
coming from lots of "legitimate" IP addresses which can not all be
blocked.

Actually part of the problem in defending against DDOS, is quite often the IP addresses are in fact being forged / spoofed (at random no less) which makes it largely impossible to determine what *actual* IP addresses the attacks are coming from. It is possible to discover this information ultimately, but literally only by tracing the traffic backwards from router to router. This of course necessitates having access to administrative staff at different network points willing to dig into the bits and bytes of the packets being sent through their equipment. That's often a tall order unfortunately.


If the IP addresses showing up at your server in a DDOS situation were the legitimate IP addresses for offending machines, filtering them out would be relatively easy in the scheme of things!




--- You are currently subscribed to e-gold-list as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED]

Use e-gold's Secure Randomized Keyboard (SRK) when accessing your e-gold account(s) via the web and shopping cart interfaces to help thwart keystroke loggers and common viruses.

Reply via email to