Date: Fri, 22 Aug 2003 19:06:51 -0400 From: "Eric L. Howard" <elh@outreachnetworks.com> To: freebsd-isp@freebsd.org Subject: Re: sobig effects - batten down the hatches Message-ID: <20030822230650.GB2990@outreachnetworks.com> In-Reply-To: <Pine.BSF.4.21.0308230722470.35459-100000@satin.sensation.net.au> References: <047a01c368f2$d0a933f0$0d3f11c8@ncrj.rnp.br> <Pine.BSF.4.21.0308230722470.35459-100000@satin.sensation.net.au>
next in thread | previous in thread | raw e-mail | index | archive | help
At a certain time, now past [Aug.23.2003-07:25:47AM +1000], rowan@sensation.net.au spake thusly: > On Fri, 22 Aug 2003, Alex Soares de Moura wrote: > > > Yes, we've applied ACLs to some destinations known it would try > > to access and in the programmed time, we started to get hits on the > > ACLs: > > > > deny ip any host 67.73.21.6 log (558 matches) > > deny ip any host 68.38.159.161 log (470 matches) [....] > > Hi Alex: > > Where did you get this list of IPs? How long ago did you see the accesses > start? I've been hunting around google and news sites, but so far I can't > find any articles that say anything more than "it will happen" ... > > Cheers. http://xforce.iss.net/xforce/alerts/id/151 scroll down to the bottom. The list of IPs hit the NANOG mailing list a little while ago and a lot of networks have null-routed the IPs already. ~elh -- Eric L. Howard e l h @ o u t r e a c h n e t w o r k s . c o m ------------------------------------------------------------------------ www.OutreachNetworks.com 313.297.9900 ------------------------------------------------------------------------ JabberID: elh@jabber.org Advocate of the Theocratic Rule
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030822230650.GB2990>