Re: Syn flood to TCP port 21 from priveleged port (80)

2016-11-01 Thread Oleg A . Arkhangelsky
01.11.2016, 22:06, "Eric Tykwinski" : > Oleg, > > I'm seeing the same to a single client here source IPs seem to be matching up > as well. > I attached a pcap, just so you can compare. > And the same sources: 141.138.128.0 - 141.138.135.255 194.73.173.0 - 194.73.173.127

Re: Syn flood to TCP port 21 from priveleged port (80)

2016-11-01 Thread Oleg A . Arkhangelsky
Hello, A couple of cuts from tcpdump output: 21:31:54.995170 IP 141.138.131.115.80 > 109.72.248.114.21: Flags [S], seq 1376379765, win 8192, length 0 21:31:55.231925 IP 194.73.173.154.80 > 109.72.241.198.21: Flags [S], seq 2254756684, win 8192, length 0 21:27:50.413927 IP 95.131.188.179.80 >

Syn flood to TCP port 21 from priveleged port (80)

2016-11-01 Thread Oleg A . Arkhangelsky

Re: Yandex DNS with Sophos antivirus blocking TrendMicro services

2015-07-27 Thread Oleg A . Arkhangelsky
25.07.2015, 19:21, Murat Kaipov mkai...@outlook.com: Hello Guys. For 2 day I experience an issue with using my trendmicro software. For some reason web check didn't worked. I try to investigate this issue and found that yandex dns services blocking all trendmicro sites. I use yandex secure

Re: Low Cost 10G Router

2015-05-19 Thread Oleg A . Arkhangelsky
19.05.2015, 21:26, Max Tulyev max...@netassist.ua: Last config I touched: 2xIntel(R) Xeon(R) CPU E5-2650 0 @ 2.00GHz, 12 Gbit summary, 5% each core load. And what PPS rate (in+out)? -- wbr, Oleg. Anarchy is about taking complete responsibility for yourself.   Alan Moore.

Re: Traffic to 5/8 and 37/8 - stats on RIPE Labs

2011-02-21 Thread Oleg A. Arkhangelsky
Hello, http://labs.ripe.net/Members/mkarir/first-impressions-of-pollution-in-two-ripe-ncc-darknets Quote from the link: Note that in the 37/8, most traffic comes from TTLs around 100. These are Linux hosts. The smaller humps are at ~32 (Windows) and ~250 (Solaris). I don't agree. TTL

blackhole-1.iana.org and blackhole-1.iana.org servers are down?

2010-12-19 Thread Oleg A. Arkhangelsky
Hello, It seems that 192.175.48.6 and 192.175.48.42 not replying to RFC1918 addresses DNS-reverse lookups. Does anybody noticed this? -- wbr, Oleg.