Of the customers I've had to shut off for being DOS targets, all are windows boxen. Perhaps there is a new windows exploit? Regards, Christopher J. Wolff, VP CIO Broadband Laboratories, Inc. http://www.bblabs.com -----Original Message----- From: owner-nanog@merit.edu [mailto:owner-nanog@merit.edu] On Behalf Of hc Sent: Friday, January 24, 2003 11:39 PM To: Joel Perez Cc: Aaron Burnett; Alex Rubenstein; nanog@merit.edu Subject: Re: Level3 routing issues? Okay this is getting bad.. one of our routers just locked up from udp 1434's. Can't even telnet to it now. -hc Joel Perez wrote:
My firewalls are going nuts with hits on UDP port 1434 also from everywhere!
-----Original Message----- From: Aaron Burnett [mailto:listkeep@yet-another.com] Sent: Sat 1/25/2003 1:19 AM To: Alex Rubenstein Cc: hc; nanog@merit.edu Subject: Re: Level3 routing issues?
On Sat, 25 Jan 2003, Alex Rubenstein wrote:
I dunno about that. But, I am seeing, in the last couple
hours, all kinds
of new traffic.
like, customers who never get attacked or anything, all of a sudden:
http://mrtg.nac.net/switch9.oct.nac.net/3865/switch9.oct.nac.net-3865.ht ml
We are seeing this on ports all across out network -- nearly
1/2 our ports
are in delta alarm right now.
Anyone else?
Yep. Since about 12:30 am. Getting pounded on UDP port 1434 from all over the world to any address on my network.