I don't think my first post made it through, so here goes again.  Our web server has 
been completely bombarded for about four hours now by a specific range of IP 
addresses.  Our T1 line has been at 100% capacity during this ordeal.  We are 
receiving around 250 packets per second from a range of IPs that I cannot completely 
trace.  

The range is 216.106.166.141 through 216.106.166.141.  All packets appear to be legit 
http requests for port 80.  The requests cycle through from one IP after the next and 
then the cycle starts over.  I have tried using http://www.network-tools.com to trace 
the numbers to no avail.  I can only get within the last five nodes before the trace 
times out.

Does anyone have any ideas what this may be?  I'm thinking maybe a new worm or a DOS 
but I'm not sure yet.  Thanks in advance.

Seth Keller
Culver Community Schools
A+/N+/CIW
Intel Certified Integration Specialist 2000/2001

Reply via email to