[nsp-sec] DDoS to MyDynDNS: Look for flows?
Tom Daly
tom at dyn.com
Fri Oct 30 12:17:24 EDT 2009
> I'm attaching a list of source IPs we saw involved. At this time,
> we're unsure if this was spoofed sources or not.
Hi Folks,
A histogram of TTLs for ORD, where ns2 is located.
TTL | Occurances
16 2
17 3
24 9
26 18
30 5
31 43
32 2
33 16
34 1
35 2
37 10
41 12
42 27
43 41
45 95
46 313
47 138
48 59
49 53
50 51
51 67
52 45
53 87
54 11
55 25
58 2
105 2
106 1
107 140
108 247
109 267
110 662
111 468
112 564
113 785
114 1081
115 1362
116 1385
117 839
118 725
119 224
120 43
121 49
242 16
243 1
247 2
Legit 0wned Windows hosts?
Thanks,
Tom
More information about the nsp-security
mailing list