[nsp-sec] 15 Gbps TCP SYN DoS

Jason Chambers jchambers at ucla.edu
Sat Apr 20 02:27:40 EDT 2013


Hello all,

Earlier today during lunchtime we experienced a 15 Gbps DoS attack 
directed towards 128.97.25.146.

The traffic was SYN flood to TCP/80.  This server wasn't running an 
official web server so consider any traffic towards that IP/Port as suspect.

If you find anything interesting we'd appreciate hearing it.

Start: 2013/04/19T18:50:00
Stop:  2013/04/19T19:50:00 (null routed)


Regards,

--Jason



More information about the nsp-security mailing list