[nsp-sec] YARL v2

Krista Hickey Krista.Hickey at cogeco.com
Fri Jun 7 01:54:33 EDT 2013


Three more DNS resolver attacks, two are from late last week as they got stuck in my outbox.

File 670596, which is an attack from yesterday, is only ~300 hosts but 2.2Gbps for the 5 minute attack, 134 of the hosts were pushing 50Mbps+
during the attack. The following 7 hosts were 100Mbps+

11769   | 64.63.0.15       | 64.63.0.0/24        | US | arin     | 2000-03-16 | MOBILENETICS-LA-GW1 - Mobilenetics Corporation
16713   | 64.146.180.187   | 64.146.128.0/17     | US | arin     | 2001-09-13 | NOANET-WA - Northwest Open Access Network
6939    | 64.71.146.250    | 64.71.128.0/18      | US | arin     | 2000-04-19 | HURRICANE - Hurricane Electric, Inc
600     | 192.88.193.144   | 192.88.193.0/24     | US | arin     | 1990-12-20 | OARNET-AS - OARnet
21623   | 65.50.225.98     | 65.50.224.0/19      | US | arin     | 2010-11-03 | SPACELINK - Spacelink Systems
13768   | 64.34.195.234    | 64.34.192.0/21      | US | arin     | 2004-07-15 | PEER1 - Peer 1 Network Inc.
39869   | 89.107.158.146   | 89.107.152.0/21     | PL | ripencc  | 2006-05-04 | SITEL-PL SITEL - Polish IP Transit Networks

As before, I can be more specific with the target if you plan on tracing (please do), otherwise share as required for mitigation, no attribution
and strip the target unless absolutely necessary.

Thanks
Krista


-------------- next part --------------
A non-text attachment was scrubbed...
Name: 627836
Type: application/octet-stream
Size: 250022 bytes
Desc: 627836
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20130607/a8266a2e/attachment-0003.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 651995
Type: application/octet-stream
Size: 251205 bytes
Desc: 651995
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20130607/a8266a2e/attachment-0004.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 670596
Type: application/octet-stream
Size: 36252 bytes
Desc: 670596
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20130607/a8266a2e/attachment-0005.obj>


More information about the nsp-security mailing list