ICANN Targets DDoS Attacks

Peter E. Fry pfry at swbell.net
Wed Oct 30 04:49:15 UTC 2002


On 29 Oct 2002 at 20:51, Brett Frankenberger wrote:

  Brett!  Long time, no hear, now that the Nortel/Bay newsgroup has 
pretty much wound down.  Like Usenet in general.

> Addressing just the issue of how traceroute works, I'll point out that
> (a) Most or all flavors of traceroute distributed by Microsoft use ICMP
> ECHO instead of UDP for the outbound packets [...]

   ...And I rather like that method.  It's sad, but I'll not allow 
random high-port UDP to my stations.

> FWIW, I don't think rate limiting ICMP is likely to have a negative
> impact.  I also don't think it's a good idea, though -- it might help
> to identify or prevent some problems in the short term, but in the long
> run, it's a race we can't win [...]

  Hmmm.  Agreed.

Peter E. Fry




More information about the NANOG mailing list