Did Wanadoo, French ISP, block access to SCO?

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Sun Feb 1 23:09:55 UTC 2004


On Sun, 01 Feb 2004 20:00:40 -0200, "Rubens Kuhl Jr." <rubens at email.com>  said:
> 
> And by blackholing that IP they've also blackholed www.caldera.com, which is
> currently not a DDoS target but is also not respondig to requests.

Umm,, I'll bite.  If www.sco.com and www.caldera.com are on the same IP,
how do you create a DDoS that wouldn't take out the Caldera site as well?

A sheer-traffic DDoS will hurt both.  A synflood will hurt both.

The webserver that's listening on port 80 doesn't know which site
is being connected to until it actually reads in the HTTP/1.1 headers and
looks at the Host: tag - and if there's enough things arriving with
'Host: www.sco.com', it will require some *very* creative filtering/limiting
to keep one website working while the other is down....
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20040201/c5ee1a0e/attachment.sig>


More information about the NANOG mailing list