DNS noise

Michael Sinatra michael at rancid.berkeley.edu
Fri Apr 6 17:51:50 UTC 2012


On 04/06/12 10:47, Keegan Holley wrote:
> Have you tried contacting the owner of the IP?  A DDOS attack from that
> particular IP would be ironic.
>
> #
> # The following results may also be obtained via:
> #
> http://whois.arin.net/rest/nets;q=72.20.23.24?showDetails=true&showARIN=false&ext=netref2
> #
>
> Staminus Communications STAMINUS-COMMUNICATIONS (NET-72-20-0-0-1) 72.20.0.0
> - 72.20.63.255
> DDOSWIZ.COM STAMINUS-COMMUNICATIONS (NET-72-20-23-0-1) 72.20.23.0 -
> 72.20.23.63

If it's an attempt at a reflective DNS-based DDoS attack, then the 
source IP address making the query is likely spoofed.  The IP address in 
question is really the target, not the source of the attack.

That is, of course, if this is a standard reflective DDoS attack.

michael




More information about the NANOG mailing list