On 31 Mar 2013, at 17:09, Vernon Schryver <[email protected]> wrote: > What's the profit for the bad guy in spending 10 bps of botnet > bandwidth to reflect 9 bps at the target?
Having the reflected traffic appear to come from trusted name servers instead of his botnet perhaps? Though since the botnet almost certainly won't implement BCP38, I suppose the bad guy could put bogus source addresses in the outgoing packets anyway, _______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs
