ICMP Attacks???????

Alex "Mr. Worf" Yuriev alex at netaxs.com
Fri Aug 22 01:39:44 UTC 1997

> Short of fixing every network on the internet, does anyone have any useful
> advice for what to do when smurfed?  This happened to an FDT customer last
> night, and it had our T1 (according to uunet) at about 500% capacity.
> Obviously, until the attack stopped, our T1 wasn't too useful.  I'm about
> >< close to just asking uunet to block all icmp echo replies from coming
> into FDT...but I know customers will complain.

Then they will start blasting UDP at you. Trust me, T1 is not that bad. We
periodically have DS-3s eaten up completely but it happens for such a
short time that it cannot really be traced :(


