Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 22 Aug 2003 19:06:51 -0400
From:      "Eric L. Howard" <elh@outreachnetworks.com>
To:        freebsd-isp@freebsd.org
Subject:   Re: sobig effects - batten down the hatches
Message-ID:  <20030822230650.GB2990@outreachnetworks.com>
In-Reply-To: <Pine.BSF.4.21.0308230722470.35459-100000@satin.sensation.net.au>
References:  <047a01c368f2$d0a933f0$0d3f11c8@ncrj.rnp.br> <Pine.BSF.4.21.0308230722470.35459-100000@satin.sensation.net.au>

next in thread | previous in thread | raw e-mail | index | archive | help
At a certain time, now past [Aug.23.2003-07:25:47AM +1000], rowan@sensation.net.au spake thusly:
> On Fri, 22 Aug 2003, Alex Soares de Moura wrote:
> 
> > Yes, we've applied ACLs to some destinations known it would try
> > to access and in the programmed time, we started to get hits on the
> > ACLs:
> > 
> >     deny ip any host 67.73.21.6 log (558 matches)
> >     deny ip any host 68.38.159.161 log (470 matches)
[....]
> 
> Hi Alex:
> 
> Where did you get this list of IPs? How long ago did you see the accesses
> start? I've been hunting around google and news sites, but so far I can't
> find any articles that say anything more than "it will happen" ...
> 
> Cheers.

http://xforce.iss.net/xforce/alerts/id/151  scroll down to the bottom.

The list of IPs hit the NANOG mailing list a little while ago and a lot of
networks have null-routed the IPs already.

       ~elh

-- 
Eric L. Howard           e l h @ o u t r e a c h n e t w o r k s . c o m
------------------------------------------------------------------------
www.OutreachNetworks.com                                    313.297.9900
------------------------------------------------------------------------
JabberID: elh@jabber.org                 Advocate of the Theocratic Rule



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030822230650.GB2990>