[nsp-sec] DDoS to MyDynDNS: Look for flows?

Tom Daly tom at dyn.com
Fri Oct 30 08:56:17 EDT 2009


Hi Folks,
As of 0920 UTC, ns[1-5].mydyndns.org have become subject to a series of DDoS attacks.

We're seeing random source IPs attack our nameservers. Destination ports are random, payload is 1000-bytes of random chars.

We've mitigated at our edge. Compiling sources now.

Hoping folks wouldn't mind looking for flows to the following IPs and tracing back, if possible.

91.198.22.76
204.13.248.76
204.13.249.76
208.78.69.76
203.62.195.76

Thanks,
Tom

-- 
Tom Daly
CTO, Dynamic Network Services, Inc.
Ph: 603-296-1537
http://dyn.com/




More information about the nsp-security mailing list