Its been a long time since I have seen one our network have an attack
like that
but we try do all we can to prevent this by doing levels of route
filtering and firewall filtering.
It can easily happen with a router like a customers mikrotik with no
rule to drop incoming dns request to the router.
On 01/26/2015 01:02 PM, TJ Trout wrote:
I usually use mikrotik torch to find the victim ip and have my
upstream null it, what options are available for mitigation besides
null routing at the upstream provider ?
On Jan 26, 2015 10:50 AM, "timothy steele" <[email protected]
<mailto:[email protected]>> wrote:
What filter do you guys use on wireshark to find a DDOS attack?
It's been about 7yrs sense I've done that so I'm a bit rusty..
Thanks,
—
Sent from Mailbox <https://www.dropbox.com/mailbox>