Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] DoS amp attack / Top20

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] DoS amp attack / Top20


Chronological Thread 
  • From: "Alex M (Coyo)" <coyo AT darkdna.net>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] DoS amp attack / Top20
  • Date: Mon, 29 Apr 2013 14:26:13 -0500

On 04/29/2013 11:13 AM, kennytaylor AT runbox.com wrote:
The source addresses are always residential ISPs. It makes me wonder if this
is the action of a botnet, the source addresses are not spoofed, and isc.org
is the real target (via the recursive query).

This is obviously the case.

We are being used.

ISC.org is the true target, and our nameservers are being used for amplification by a botnet.



Archive powered by MHonArc 2.6.19.

Top of Page