Am Wed, 12 Sep 2012 11:36:19 +0200 schrieb Klaus Darilion <[email protected]>: > I also wondered if maybe it is just a legitimate user trying to "mirror" > the DNS. But todays most seen source on our DNS servers is 113.21.221.21 > which is assinged to nexusguard.com which "protects E-Business from DDoS > attacks". This makes me believe that it is an amplification attack. >
Same here now. Earlier today (between around 1 and 5 am) it's been 222.73.0.37 though. Regards, Torsten _______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs
