31 Jan
2013
31 Jan
'13
3:02 a.m.
On Thu, Jan 31, 2013 at 11:23:11AM +0330, Shahab Vahabzadeh <sh.vahabzadeh@gmail.com> wrote a message of 55 lines which said:
Those ip addresses I send were only sample, its 5 page :D and not only those addresses.
Because the attacker attacks when they have a new opponent. They DoS it long enough to win a race, then start a new fight in the game.
And you are looking to target 128.141.X.Y its mine and I change it because of mailing list, maybe attackers are here. You must check the sources not destination.
What Jeroen said is that source IP addresses are spoofed (which is common with UDP-based protocols such as the DNS). They are the victim's addresses, not the attacker's.