On Fri, Aug 8, 2008 at 4:13 PM, Claude Schneegans
<[EMAIL PROTECTED]> wrote:
>  >>Then 20-30 minutes later he would show up again with a different IP.
>
> How do you know it was the same guy ?
> May be it was the same bot doing the same thing, but these bots are just
> like viruses,
> they spread anywhere.
>
> --

We don't.  It was definitely an automated attack (I.e., bot), but it
"felt" like it was controlled by one source/individual as opposed to
several sources doing the same attack method because as we blocked
each IP address the attack took ~20-30 minutes to begin again (I.e.,
switch IP address).  And each chunk of attacks were all coming from a
solitary IP address (which is why we began blocking them).

Errata: Below I meant "IPs" to be "ISPs".
  "So how is anyone going to be able to effectively communicate with
these IPs to tell them about the compromised systems on their network?
 The problem becomes even more difficult to enforce since IPs don't
necessarily want to offend their paying customers."

Eric Pierce

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Adobe® ColdFusion® 8 software 8 is the most important and dramatic release to 
date
Get the Free Trial
http://ad.doubleclick.net/clk;203748912;27390454;j

Archive: 
http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:310576
Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4

Reply via email to