What do the packets/rrequests look like? On Nov 21, "Seth Keller" <[EMAIL PROTECTED]> wrote: > > I don't think my first post made it through, so here goes again. Our web server has been completely bombarded for about four hours now by a specific range of IP addresses. Our T1 line has been at 100% capacity during this ordeal. We are receiving around 250 packets per second from a range of IPs that I cannot completely trace. > > The range is 216.106.166.141 through 216.106.166.141. All packets appear to be >legit http requests for port 80. The requests cycle through from one IP after the next and then the cycle starts over. I have tried using <a href='http://www.network- tools.com'>http://www.network-tools.com</a> to trace the numbers to no avail. I can only get within the last five nodes before the trace times out. > > Does anyone have any ideas what this may be? I'm thinking maybe a new worm or a DOS but I'm not sure yet. Thanks in advance. > > Seth Keller > Culver Community Schools > A+/N+/CIW > Intel Certified Integration Specialist 2000/2001 > > >
Adrien de Beaupr�, BA, MCSE, GCIH, CISSP IT Security Specialist
