[nsp-sec] 6700 Chargen Reflectors

Krista Hickey Krista.Hickey at cogeco.com
Wed Jun 26 09:25:17 EDT 2013


Blast from the past...well not really as this is fairly prevalent but this 5Gbps gaming related attack early this morning caught my attention and then noticed it's using good ole Chargen reflectors. Fairly certain few of you have legitimate reason to have hosts responding to chargen on your network so attached is some fodder for internal discussion. They also have statically set the destination port so you should also be able to look for flows/logs to my target on destination port 2070/udp

As before, share as required for mitigation, no attribution, strip the target unless necessary and if you need the /32 just contact me offlist.

Krista
7992
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 652808
Type: application/octet-stream
Size: 795144 bytes
Desc: 652808
URL: <https://puck.nether.net/mailman/private/nsp-security/attachments/20130626/3af3d7e9/attachment-0001.obj>


More information about the nsp-security mailing list