Cisco/Level3 takedown

Steve Mikulasik Steve.Mikulasik at civeo.com
Thu Apr 9 16:06:17 UTC 2015


Seems like it this is pretty ineffective. The group already moved subnets once, they will likely do this again, all Cisco/L3 have done is slow them down a bit. 

Stephen Mikulasik

-----Original Message-----
From: NANOG [mailto:nanog-bounces at nanog.org] On Behalf Of Sameer Khosla
Sent: Thursday, April 09, 2015 9:31 AM
To: nanog at nanog.org
Subject: Cisco/Level3 takedown

Was just reading http://blogs.cisco.com/security/talos/sshpsychos then checking my routing tables.

Looks like the two /23's they mention are now being advertised as /24's, and I'm also not sure why cisco published the ssh attack dictionary.

It seems to me that this is something that if they want to do, they should be working with entire service provider community, not just one provider.


Thanks

Sameer Khosla
Managing Director
Neutral Data Centers Corp.
Twitter: @skhoslaTO





More information about the NANOG mailing list