Re: [WISPA] be on the look out for this

2014-01-18 Thread Justin Wilson
http://threatpost.com/us-cert-warns-of-ntp-amplification-attacks/103573 From: Gary Garrett Reply-To: WISPA General List Date: Saturday, January 18, 2014 at 9:43 PM To: WISPA General List Subject: Re: [WISPA] be on the look out for this > > > They spoofed one of my IP

Re: [WISPA] be on the look out for this

2014-01-18 Thread Gary Garrett
t: *Saturday, January 18, 2014 2:39:21 AM *Subject: *Re: [WISPA] be on the look out for this We got hit by this. Real Bummer. 4,000 connections pounding ports 123 and 19 on one IP address. 30 meg sustained and 70 - 80 meg peaks. Took down the entire 100 meg fiber due to the massive packets per s

Re: [WISPA] be on the look out for this

2014-01-18 Thread Mike Hammett
Were you the target or the "source"? - Mike Hammett Intelligent Computing Solutions http://www.ics-il.com - Original Message - From: "Gary Garrett" To: "WISPA General List" Sent: Saturday, January 18, 2014 2:39:21 AM Subject: Re: [WISP

Re: [WISPA] be on the look out for this

2014-01-18 Thread Clay Stewart
It is a lot cheaper then that... here is an old article of the first botnet herder going public on how it is done, and at $15. http://www.forbes.com/sites/eliseackerman/2012/05/19/i-run-a-small-botnet-and-sell-stolen-information-ask-me-anything/ On Sat, Jan 18, 2014 at 3:39 AM, Gary Garrett wro

Re: [WISPA] be on the look out for this

2014-01-18 Thread Gary Garrett
We got hit by this. Real Bummer. 4,000 connections pounding ports 123 and 19 on one IP address. 30 meg sustained and 70 - 80 meg peaks. Took down the entire 100 meg fiber due to the massive packets per second. It is still ongoing but our upstream had to block it at the edge and is still eating

Re: [WISPA] be on the look out for this

2014-01-17 Thread Butch Evans
On 01/17/2014 10:46 AM, Clay Stewart wrote: > I would assume using NTP servers that do not use Monlist which are?? > Newer than v4.2.7. Also, with a firewall, you can block the traffic coming INTO your network with (logic rules): chain: forward for routers, input for servers * permit estab

Re: [WISPA] be on the look out for this

2014-01-17 Thread Phil Curnutt
was the solution? >> >> >> >> >> >> - Original Message - >> >> From: Joe Miller >> >> To: 'WISPA General List' >> >> Sent: Friday, January 17, 2014 9:24 AM >> >> Subject: [WISPA] be on the l

Re: [WISPA] be on the look out for this

2014-01-17 Thread Clay Stewart
oadband.net> wrote: > >> > >> > >> What was the solution? > >> > >> > >> - Original Message - > >> From: Joe Miller > >> To: 'WISPA General List' > >> Sent: Friday, January 17, 2014 9:24 AM > >> Subject: [WISPA] be

Re: [WISPA] be on the look out for this

2014-01-17 Thread Phil Curnutt
B - Jay Fuller < par...@cyberbroadband.net> wrote: >> >> >> What was the solution? >> >> >> - Original Message - >> From: Joe Miller >> To: 'WISPA General List' >> Sent: Friday, January 17, 2014 9:24 AM >> Subject: [WISPA] be on the

Re: [WISPA] be on the look out for this

2014-01-17 Thread Clay Stewart
General List' > *Sent:* Friday, January 17, 2014 9:24 AM > *Subject:* [WISPA] be on the look out for this > > We had a network outage yesterday afternoon, and thanks to Mike Francis > at JMF Solutions the problem went away. So, anyone who needs network help…I > would strongly re

Re: [WISPA] be on the look out for this

2014-01-17 Thread CBB - Jay Fuller
What was the solution? - Original Message - From: Joe Miller To: 'WISPA General List' Sent: Friday, January 17, 2014 9:24 AM Subject: [WISPA] be on the look out for this We had a network outage yesterday afternoon, and thanks to Mike Francis at JMF Solutions t

[WISPA] be on the look out for this

2014-01-17 Thread Joe Miller
We had a network outage yesterday afternoon, and thanks to Mike Francis at JMF Solutions the problem went away. So, anyone who needs network help.I would strongly recommend Mike Francis at JMF Solutions. Kudos to Mike Francis. http://threatpost.com/us-cert-warns-of-ntp-amplification-attacks