[nsp-sec] UDP DDoS to PDNS1.ULTRADNS.NET and PDNS5.ULTRADNS.INFO

sthaug at nethelp.no sthaug at nethelp.no
Thu Jun 18 13:13:03 EDT 2009


> > Here is the actual full list:
> > 
> > https://asn.cymru.com/nsp-sec/upload/1245339888.whois.txt
> > 
> > time range was from 12:56 to 15:18 UTC.
> 
> I believe you have some false positives in that list. One of the hosts
> from AS 2116, 193.75.110.78, is one of our main recursive name servers,
> and is definitely expected to send queries to the UltraDNS hosts.

Oh yeah, the same applies to the 194.19.2.10 host from AS 3307.

Steinar Haug, AS 2116



More information about the nsp-security mailing list