[nsp-sec] Anyone else seeing a HUGE increase in TCP/1935 from Limelight Networks

John Fraizer john at op-sec.us
Mon Jun 16 16:03:55 EDT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Matthew.Swaar at us-cert.gov wrote:
> John,
> 
> I'm not seeing an increase in my flows for the first 19 hours of today.
> 
> V/R,
> Matt Swaar
> US-CERT Analyst

I'm having to take some drastic measures to mitigate this one.  Anyone else seeing anything spooky here?  I'm seeing it from more than just the limelight /18 as well.  It's
pretty much coming from everywhere and is shotgunned across all of our address space.

Any clue from any direction is greatly appreciated.

John
AS11456 | AS6981


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with Mandriva - http://enigmail.mozdev.org

iD8DBQFIVscr+16lRpJszIgRAgUUAJ9ec+6f5x3cL2R5pP2X3HljQWBOkQCeK0YV
dqkXOovE4m1DBSoSkAjwwXk=
=YVNh
-----END PGP SIGNATURE-----



More information about the nsp-security mailing list