Odd DDoS, anyone else seen this?
bdragon at gweep.net
bdragon at gweep.net
Fri Nov 29 23:35:39 UTC 2002
> Looked just like a regular SYN flood to the target IP. Not sure why they
> picked source addresses that were so obviously bogus though.
>
> Can anyone think of a reason why this sort of traffic should be routed at
> all? Does anyone actually drop hosts on to addresses ending in x.x.x.0?
x.x.0.0 is a valid ip address for networks with bit lengths of 0 through 15.
And yes, folks do use /32 and /31 addresses which end in .0.
> Rich
More information about the NANOG
mailing list