Re: [swinog] massive udp attacks from 67.228.4.81

2008-06-02 Diskussionsfäden Marco Fretz
hi, of course im just fighting the symptoms but it worked for us and for this weekend :-) any idea what the disease is? on Friday in the evening it suddenly stopped after about 44 millions of packets. and know only silence from this source... from which sources are u experiencing this UDP

Re: [swinog] massive udp attacks from 67.228.4.81

2008-06-01 Diskussionsfäden Tobias Göller
Hello, Since the protocol is UDP I wouldn't be too surprised if effective sender is using multiple hosts to send UDP Data. So in fact, what you're doing, is just fighting the symptoms and not the desease. I have certain doubts that subxtreme.net is the real origin. I myself am

[swinog] massive udp attacks from 67.228.4.81

2008-05-30 Diskussionsfäden Marco Fretz
Hi everybody, is there anyone else expecting massive UDP (mostly port 53) traffic from 67.228.4.81? Destinations are (possibly random chosen) ip address out of our AS3915. see attached netflow graph. We've now blocked the ip address and got over 3.7 million blocks within 10 minutes. I just