nanog mailing list archives
RE: DDOS anecdotes
From: Tim Wilde <twilde () dyndns org>
Date: Sat, 23 Jun 2001 14:37:33 -0400 (EDT)
This is a real problem. It's not FUD. Microsofts choice to include full IP stack capabilities will make the problem worse, but I do not blame their IP stack for this like Mr Gibson does though.
Oh, it's most certainly a real problem, but I don't agree that the changes in Win XP will really make any difference whatsoever. With some very trivial driver additions, raw sockets can be accessed under any previous version of Windows, just like in XP. That's where the FUD comes in - Gibson, it seems, is just trying to drum up support for whatever his next big project is to magically make your computer safe.
What should we do?
Well, like has already been mentioned, somehow getting people to filter properly could help - we got hit by a (unrelated, we think) spoofed SYN flood a few days back. If that ISP had simply egress filtered their traffic, that person using a single machine (only guessing here) couldn't have sent their 200k/sec of spoofed SYN at us. I'm sure they could have found another way, but it would have made them work a little harder, and this type of person often doesn't want to bother with that extra little bit of work, and would just give up. Tim -- Tim Wilde twilde () dyndns org Systems Administrator Dynamic DNS Network Services http://www.dyndns.org/
Current thread:
- DDOS anecdotes Sean M. Doran (Jun 23)
- Re: DDOS anecdotes Mikael Abrahamsson (Jun 23)
- Re: DDOS anecdotes Pim van Riezen (Jun 23)
- Re: DDOS anecdotes Mikael Abrahamsson (Jun 23)
- Re: DDOS anecdotes Charles Sprickman (Jun 24)
- Re: DDOS anecdotes Pim van Riezen (Jun 23)
- RE: DDOS anecdotes Vivien M. (Jun 23)
- RE: DDOS anecdotes Mikael Abrahamsson (Jun 23)
- RE: DDOS anecdotes Tim Wilde (Jun 23)
- peering requirements (Re: DDOS anecdotes) Paul Vixie (Jun 23)
- Re: peering requirements (Re: DDOS anecdotes) Eric Oosting (Jun 23)
- Re: peering requirements (Re: DDOS anecdotes) Roland Dobbins (Jun 23)
- Re: peering requirements (Re: DDOS anecdotes) Simon Lyall (Jun 23)
- Re: peering requirements (Re: DDOS anecdotes) Roland Dobbins (Jun 23)
- What is evil: IP spoofing or Distributed attacks? (was Re: DDOS anecdotes) Przemyslaw Karwasiecki (Jun 23)
- RE: DDOS anecdotes Mikael Abrahamsson (Jun 23)
- Re: peering requirements (Re: DDOS anecdotes) Paul Vixie (Jun 26)
- RE: peering requirements (Re: DDOS anecdotes) Przemyslaw Karwasiecki (Jun 26)
- Re: peering requirements (Re: DDOS anecdotes) Paul A Vixie (Jun 26)
- Re: DDOS anecdotes Mikael Abrahamsson (Jun 23)
- Re: peering requirements (Re: DDOS anecdotes) Randy Bush (Jun 26)
