At about 17:40 EDT today we started seeing traffic from
planet-lab.orgnodes at 25+ US universities all directed at one of our
hosting boxes.  Its
all ICMP and high port UDP stuff.  Nothing terrible from what we can tell,
but its triggering a constant stream of IDS alerts and auto-blocks.  Not
easy to configure for since the traffic originates from subnets all over
the place, and the list of originating nodes is growing every few minutes.

Its horribly annoying, and trying to determine the source using the tools
provided on the planet-lab.org site is pretty much impossible as the search
tool returns nothing at all times.  Yes, we've opened a ticket with
supp...@planet-lab.org already.

Has anyone else had to deal with this, or is anyone connected to that
particular project listening?  Im all for academic projects, but the
approach here is rubbing me the wrong way.

Reply via email to