Re: Weird attack or traffic (Was Re: The impending DDoS storm)

2003-08-15 Thread Haesu
It kinda looks like the virus or whatever it is, is spoofing source IP. Now I am seeing lots of spoofed packets trying to egress out of our network. We are filtering egress traffic so obviously its being dropped at edge of course... Just cleared access-list counter about a minute or so ago

Re: The impending DDoS storm

2003-08-14 Thread Mark Vallar
Jack Bates Wrote: I have no affiliation with Microsoft, nor do I care about their services or products. What I do care about is a worm that sends out packets uncontrolled. If there is the possibility that this planned DOS will cause issues with my topology, then I will do whatever it takes

The impending DDoS storm

2003-08-14 Thread Jason Frisvold
All, What is everyone doing, if anything, to prevent the apparent upcoming DDoS attack against Microsoft? From what I've been reading, and what I've been told, August 16th is the apparent start date... We're looking for some solution to prevent wasting our network resources

Re: The impending DDoS storm

2003-08-14 Thread Michael Painter
http://www.dslreports.com/forum/remark,7652257~root=security,1~mode=flat;start=0 - Original Message - From: Josh Fleishman [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, August 14, 2003 5:24 AM Subject: RE: The impending DDoS storm Has anyone determined a method

Re: The impending DDoS storm

2003-08-14 Thread Jack Bates
McBurnett, Jim wrote: But doesn't that mean the hacker won? If you change the DNS and a user can not get to windowsupdate, you just helped him create a better DoS than he had... I have no affiliation with Microsoft, nor do I care about their services or products. What I do care about is a worm

Re: The impending DDoS storm

2003-08-14 Thread Dan Hollis
On Wed, 13 Aug 2003, Jason Frisvold wrote: If the blaster cannot get a proper DNS response, it continues to replicate via port 135... It then goes into a retry cycle and continues to try to get a good DNS lookup. has anyone tried tarpitting eg labrea to slow the worm? -Dan -- [-] Omae no

RE: The impending DDoS storm

2003-08-14 Thread Christopher Chin
Today at 11:24 (-0400), Josh Fleishman wrote: Date: Thu, 14 Aug 2003 11:24:53 -0400 From: Josh Fleishman [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: RE: The impending DDoS storm Has anyone determined a method for triggering the DOS attack manually? We've attempted this by changing

RE: The impending DDoS storm

2003-08-14 Thread Kevin Houle
--On Thursday, August 14, 2003 11:24:53 AM -0400 Josh Fleishman [EMAIL PROTECTED] wrote: Has anyone determined a method for triggering the DOS attack manually? We've attempted this by changing an infected machine's clock, however it did not work on our test box. If anyone has triggered the

RE: The impending DDoS storm

2003-08-14 Thread Josh Fleishman
] Subject: Re: The impending DDoS storm Jack Bates Wrote: I have no affiliation with Microsoft, nor do I care about their services or products. What I do care about is a worm that sends out packets uncontrolled. If there is the possibility that this planned DOS will cause issues with my

RE: The impending DDoS storm

2003-08-14 Thread Jason Frisvold
PROTECTED] Subject: Re: The impending DDoS storm On Wed, 13 Aug 2003, Jason Frisvold wrote: All, What is everyone doing, if anything, to prevent the apparent upcoming DDoS attack against Microsoft? From what I've been reading, and what I've been told, August 16th

RE: The impending DDoS storm

2003-08-14 Thread Jason Frisvold
=== -Original Message- From: Jason Frisvold [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 13, 2003 10:50 AM To: Ingevaldson, Dan (ISS Atlanta) Cc: Stephen J. Wilcox; [EMAIL PROTECTED] Subject: RE: The impending DDoS storm On Wed, 2003-08-13 at 10:14, Ingevaldson, Dan (ISS

Re: The impending DDoS storm

2003-08-14 Thread Stephen J. Wilcox
On Wed, 13 Aug 2003, Jason Frisvold wrote: All, What is everyone doing, if anything, to prevent the apparent upcoming DDoS attack against Microsoft? From what I've been reading, and what I've been told, August 16th is the apparent start date... We're looking for some

Re: The impending DDoS storm

2003-08-14 Thread Jeff Kell
Dan Hollis wrote: On Wed, 13 Aug 2003, Jason Frisvold wrote: If the blaster cannot get a proper DNS response, it continues to replicate via port 135... It then goes into a retry cycle and continues to try to get a good DNS lookup. has anyone tried tarpitting eg labrea to slow the worm? Oh yeah,

Weird attack or traffic (Was Re: The impending DDoS storm)

2003-08-14 Thread Haesu
Is anyone else seeing backscatters on your network about windowsupdate.com's IP? Someone who transits through 65.123.21.137 router is sending out lots of packets to 204.79.188.11 (windowsupdate.com) in which its not currently advertised to internet as we speak. Not to mention, packets seem to be

Re: Weird attack or traffic (Was Re: The impending DDoS storm)

2003-08-14 Thread Mike Tancsa
Yes, we are starting to see this as well. We are filtering at the edge, so the bogus packets are not getting out. We have a /19 of 64.7.128.0/19 and 64.7.229.241 is totally bogus for our network. Aug 14 21:59:16 telus-151front /kernel: ipfw: 3 Deny TCP 64.7.229.241:1069