Me not being the BGP guru, I unfortunately have absolutely none. Forrest is actually doing that on our side.
On Mon, Jan 26, 2015 at 3:09 PM, James Howard <[email protected]> wrote: > That’s on my to-do list…… Any tips? > > > > *From:* Af [mailto:[email protected]] *On Behalf Of *Steve Utick > *Sent:* Monday, January 26, 2015 3:57 PM > *To:* [email protected] > *Subject:* Re: [AFMUG] Wireshark filter for DDOS attack? > > > > At the moment, we call our upstream and have them null route it. We are > working on getting a filter list set up on our core so that we can inject > it into our upstreams BGP blackhole list. > > > > On Mon, Jan 26, 2015 at 2:44 PM, James Howard <[email protected]> wrote: > > Once you’ve identified it, what do you do with it? > > > > *From:* Af [mailto:[email protected]] *On Behalf Of *Steve Utick > *Sent:* Monday, January 26, 2015 3:43 PM > *To:* [email protected] > *Subject:* Re: [AFMUG] Wireshark filter for DDOS attack? > > > > The most common thing we've been seeing lately is gamers. They are in > playing games online, and piss someone off, so they launch a DDOS towards > our customers IP to knock them out of the game. They just don't realize > that it also fills up our pipes and does way more than knock a single > customer offline. > > I've found that it's usually all UDP traffic, so I can filter for UDP and > usually get a pretty quick sense of what IP it's all destined for on our > network. Just look for the single destination IP that has traffic coming > from hundreds and thousands of different source IP addresses. > > > > On Mon, Jan 26, 2015 at 12:29 PM, David <[email protected]> wrote: > > Its been a long time since I have seen one our network have an attack like > that > but we try do all we can to prevent this by doing levels of route > filtering and firewall filtering. > It can easily happen with a router like a customers mikrotik with no rule > to drop incoming dns request to the router. > > > > > On 01/26/2015 01:02 PM, TJ Trout wrote: > > I usually use mikrotik torch to find the victim ip and have my upstream > null it, what options are available for mitigation besides null routing at > the upstream provider ? > > On Jan 26, 2015 10:50 AM, "timothy steele" <[email protected]> > wrote: > > What filter do you guys use on wireshark to find a DDOS attack? It's been > about 7yrs sense I've done that so I'm a bit rusty.. > > > > Thanks, > > > — > Sent from Mailbox <https://www.dropbox.com/mailbox> > > > > > ------------------------------ > > *Total Control Panel* > > Login <https://asp.reflexion.net/login?domain=litewire.net> > > To: [email protected] > <https://asp.reflexion.net/address-properties?aID=242260993&domain=litewire.net> > > From: > 0000014b283252fa-e8871843-4d18-4d79-b6fa-51aa09376c3c-000...@amazonses.com > <https://asp.reflexion.net/address-properties?aID=3007550797&domain=litewire.net> > > Remove > <https://asp.reflexion.net/FooterAction?ver=2&un-wl-sender-domain=1&rID=242260993&aID=3007550797&domain=litewire.net> > amazonses.com from my allow list > > *You received this message because the domain amazonses.com > <http://amazonses.com> is on your allow list.* > > > > > ------------------------------ > > *Total Control Panel* > > Login <https://asp.reflexion.net/login?domain=litewire.net> > > To: [email protected] > <https://asp.reflexion.net/address-properties?aID=242260993&domain=litewire.net> > > From: > 0000014b283f49dc-52a150b0-3bb1-4dd5-8a6e-12e7fcd7cd49-000...@amazonses.com > <https://asp.reflexion.net/address-properties?aID=3007580454&domain=litewire.net> > > Remove > <https://asp.reflexion.net/FooterAction?ver=2&un-wl-sender-domain=1&rID=242260993&aID=3007580454&domain=litewire.net> > amazonses.com from my allow list > > *You received this message because the domain amazonses.com > <http://amazonses.com> is on your allow list.* > > >
