[nsp-sec] Abnormal flows to 204.13.248.125?

Tom Daly tom at dyn.com
Mon Jun 28 00:55:25 EDT 2010


Hi Folks,
Is anyone seeing any large flows to 204.13.248.125? We're experiencing a very large DDoS attack to this host and we're looking for sources. Packets are spoofed, random source IP, TCP + syn flag set + large (>300 byte) payloads.

Any assistance would be appreciated.

Thanks,
Tom Daly

-- 
Tom Daly
CTO, Dynamic Network Services, Inc.
Ph: 603-296-1537
http://dyn.com/




More information about the nsp-security mailing list