That’s on my to-do list……   Any tips?

From: Af [mailto:[email protected]] On Behalf Of Steve Utick
Sent: Monday, January 26, 2015 3:57 PM
To: [email protected]
Subject: Re: [AFMUG] Wireshark filter for DDOS attack?

At the moment, we call our upstream and have them null route it.    We are 
working on getting a filter list set up on our core so that we can inject it 
into our upstreams BGP blackhole list.

On Mon, Jan 26, 2015 at 2:44 PM, James Howard 
<[email protected]<mailto:[email protected]>> wrote:
Once you’ve identified it, what do you do with it?

From: Af [mailto:[email protected]<mailto:[email protected]>] On Behalf 
Of Steve Utick
Sent: Monday, January 26, 2015 3:43 PM
To: [email protected]<mailto:[email protected]>
Subject: Re: [AFMUG] Wireshark filter for DDOS attack?

The most common thing we've been seeing lately is gamers.   They are in playing 
games online, and piss someone off, so they launch a DDOS towards our customers 
IP to knock them out of the game.   They just don't realize that it also fills 
up our pipes and does way more than knock a single customer offline.
I've found that it's usually all UDP traffic, so I can filter for UDP and 
usually get a pretty quick sense of what IP it's all destined for on our 
network.   Just look for the single destination IP that has traffic coming from 
hundreds and thousands of different source IP addresses.

On Mon, Jan 26, 2015 at 12:29 PM, David 
<[email protected]<mailto:[email protected]>> wrote:
Its been a long time since I have seen one our network have an attack like that
 but we try do all we can to prevent this by doing levels of route filtering 
and firewall filtering.
It can easily happen with a router like a customers mikrotik with no rule to 
drop incoming dns request to the router.


On 01/26/2015 01:02 PM, TJ Trout wrote:

I usually use mikrotik torch to find the victim ip and have my upstream null 
it, what options are available for mitigation besides null routing at the 
upstream provider ?
On Jan 26, 2015 10:50 AM, "timothy steele" 
<[email protected]<mailto:[email protected]>> wrote:
What filter do you guys use on wireshark to find a DDOS attack? It's been about 
7yrs sense I've done that so I'm a bit rusty..

Thanks,

—
Sent from Mailbox<https://www.dropbox.com/mailbox>


________________________________
Total Control Panel

Login<https://asp.reflexion.net/login?domain=litewire.net>


To: 
[email protected]<https://asp.reflexion.net/address-properties?aID=242260993&domain=litewire.net>

From: 
0000014b283252fa-e8871843-4d18-4d79-b6fa-51aa09376c3c-000...@amazonses.com<https://asp.reflexion.net/address-properties?aID=3007550797&domain=litewire.net>


Remove<https://asp.reflexion.net/FooterAction?ver=2&un-wl-sender-domain=1&rID=242260993&aID=3007550797&domain=litewire.net>
 amazonses.com<http://amazonses.com> from my allow list



You received this message because the domain 
amazonses.com<http://amazonses.com> is on your allow list.




________________________________
Total Control Panel

Login<https://asp.reflexion.net/login?domain=litewire.net>


To: 
[email protected]<https://asp.reflexion.net/address-properties?aID=242260993&domain=litewire.net>

From: 
0000014b283f49dc-52a150b0-3bb1-4dd5-8a6e-12e7fcd7cd49-000...@amazonses.com<https://asp.reflexion.net/address-properties?aID=3007580454&domain=litewire.net>


Remove<https://asp.reflexion.net/FooterAction?ver=2&un-wl-sender-domain=1&rID=242260993&aID=3007580454&domain=litewire.net>
 amazonses.com from my allow list



You received this message because the domain amazonses.com is on your allow 
list.



Reply via email to