On Nov 4, 2013, at 19:54, Justin <[email protected]> wrote:
> I have two machines that participate in the ntp pool project, and I received > an abuse email today. Basically, my server was DDOS someone else, ntp > reflection attack. Hi Justin, Can you show a tcpdump of this? I got two other DDOS related reports in the last 24 hours (which is at least 2 more than I recall getting in any given *month* or maybe even year in the last 8!). One was a straight up udp reflection attack (management packets, I think) - maybe similar to yours. The other was udp packets, but not port 123 in either end. It looked like it was just a straight up "dump traffic that way" attack. That was multiple gigabits though. Ask _______________________________________________ pool mailing list [email protected] http://lists.ntp.org/listinfo/pool
