Getting hit hard by CHINANET

Roland Dobbins rdobbins at arbor.net
Wed Mar 18 02:16:11 UTC 2015


On 18 Mar 2015, at 9:13, Roland Dobbins wrote:

> Also, asking your upstreams/peers to block traffic sourced from this 
> IP to your netblock(s) on their networks.

It would also be a good idea to ensure that your systems which are being 
targeted aren't themselves compromised, and being used by miscreants as 
botnet C&Cs or whatever.  A lot of 'inexplicable' attacks are actually 
internecine disputes amongst miscreants, with compromised systems under 
the control of miscreant A being targeted by miscreant B - and the 
legitimate owner/operator of the hosts in question has no idea that 
they're compromised.

-----------------------------------
Roland Dobbins <rdobbins at arbor.net>


More information about the NANOG mailing list