What do the packets/rrequests look like?

On Nov 21, "Seth Keller" <[EMAIL PROTECTED]> wrote:
> 
> I don't think my first post made it through, so here goes again.  Our web server has 
been completely bombarded for about four hours now by a specific range of IP 
addresses.  
Our T1 line has been at 100% capacity during this ordeal.  We are receiving around 250 
packets per second from a range of IPs that I cannot completely trace.  
> 
> The range is 216.106.166.141 through 216.106.166.141.  All packets appear to be 
>legit 
http requests for port 80.  The requests cycle through from one IP after the next and 
then the cycle starts over.  I have tried using <a href='http://www.network-
tools.com'>http://www.network-tools.com</a> to trace the numbers to no avail.  I can 
only 
get within the last five nodes before the trace times out.
> 
> Does anyone have any ideas what this may be?  I'm thinking maybe a new worm or a DOS 
but I'm not sure yet.  Thanks in advance.
> 
> Seth Keller
> Culver Community Schools
> A+/N+/CIW
> Intel Certified Integration Specialist 2000/2001
> 
> 
> 

Adrien de Beaupr�, BA, MCSE, GCIH, CISSP
IT Security Specialist

Reply via email to