26 Feb
2016
26 Feb
'16
3:58 a.m.
On 26 Feb 2016, at 10:52, Paras Jha wrote:
You don't typically see DNS amplified floods coming from home ISPs.
Actually, it's quite common, as a lot of CPE have abusable DNS forwarders running on their public interfaces. DNS, SSDP, and SNMP reflection/amplification quite commonly emanate from broadband access networks due to abusable CPE. Others, as well, of course, but those are generally the most prevalent. ----------------------------------- Roland Dobbins <rdobbins@arbor.net>