Me not being the BGP guru, I unfortunately have absolutely none.   Forrest
is actually doing that on our side.


On Mon, Jan 26, 2015 at 3:09 PM, James Howard <[email protected]> wrote:

> That’s on my to-do list……   Any tips?
>
>
>
> *From:* Af [mailto:[email protected]] *On Behalf Of *Steve Utick
> *Sent:* Monday, January 26, 2015 3:57 PM
> *To:* [email protected]
> *Subject:* Re: [AFMUG] Wireshark filter for DDOS attack?
>
>
>
> At the moment, we call our upstream and have them null route it.    We are
> working on getting a filter list set up on our core so that we can inject
> it into our upstreams BGP blackhole list.
>
>
>
> On Mon, Jan 26, 2015 at 2:44 PM, James Howard <[email protected]> wrote:
>
> Once you’ve identified it, what do you do with it?
>
>
>
> *From:* Af [mailto:[email protected]] *On Behalf Of *Steve Utick
> *Sent:* Monday, January 26, 2015 3:43 PM
> *To:* [email protected]
> *Subject:* Re: [AFMUG] Wireshark filter for DDOS attack?
>
>
>
> The most common thing we've been seeing lately is gamers.   They are in
> playing games online, and piss someone off, so they launch a DDOS towards
> our customers IP to knock them out of the game.   They just don't realize
> that it also fills up our pipes and does way more than knock a single
> customer offline.
>
> I've found that it's usually all UDP traffic, so I can filter for UDP and
> usually get a pretty quick sense of what IP it's all destined for on our
> network.   Just look for the single destination IP that has traffic coming
> from hundreds and thousands of different source IP addresses.
>
>
>
> On Mon, Jan 26, 2015 at 12:29 PM, David <[email protected]> wrote:
>
> Its been a long time since I have seen one our network have an attack like
> that
>  but we try do all we can to prevent this by doing levels of route
> filtering and firewall filtering.
> It can easily happen with a router like a customers mikrotik with no rule
> to drop incoming dns request to the router.
>
>
>
>
> On 01/26/2015 01:02 PM, TJ Trout wrote:
>
> I usually use mikrotik torch to find the victim ip and have my upstream
> null it, what options are available for mitigation besides null routing at
> the upstream provider ?
>
> On Jan 26, 2015 10:50 AM, "timothy steele" <[email protected]>
> wrote:
>
> What filter do you guys use on wireshark to find a DDOS attack? It's been
> about 7yrs sense I've done that so I'm a bit rusty..
>
>
>
> Thanks,
>
>
> —
> Sent from Mailbox <https://www.dropbox.com/mailbox>
>
>
>
>
> ------------------------------
>
> *Total Control Panel*
>
> Login <https://asp.reflexion.net/login?domain=litewire.net>
>
> To: [email protected]
> <https://asp.reflexion.net/address-properties?aID=242260993&domain=litewire.net>
>
> From:
> 0000014b283252fa-e8871843-4d18-4d79-b6fa-51aa09376c3c-000...@amazonses.com
> <https://asp.reflexion.net/address-properties?aID=3007550797&domain=litewire.net>
>
> Remove
> <https://asp.reflexion.net/FooterAction?ver=2&un-wl-sender-domain=1&rID=242260993&aID=3007550797&domain=litewire.net>
> amazonses.com from my allow list
>
> *You received this message because the domain amazonses.com
> <http://amazonses.com> is on your allow list.*
>
>
>
>
> ------------------------------
>
> *Total Control Panel*
>
> Login <https://asp.reflexion.net/login?domain=litewire.net>
>
> To: [email protected]
> <https://asp.reflexion.net/address-properties?aID=242260993&domain=litewire.net>
>
> From:
> 0000014b283f49dc-52a150b0-3bb1-4dd5-8a6e-12e7fcd7cd49-000...@amazonses.com
> <https://asp.reflexion.net/address-properties?aID=3007580454&domain=litewire.net>
>
> Remove
> <https://asp.reflexion.net/FooterAction?ver=2&un-wl-sender-domain=1&rID=242260993&aID=3007580454&domain=litewire.net>
> amazonses.com from my allow list
>
> *You received this message because the domain amazonses.com
> <http://amazonses.com> is on your allow list.*
>
>
>

Reply via email to