North American Network Operators Group|
Date Prev | Date Next |
Date Index |
Thread Index |
Author Index |
Re: SMURF amplifier block list
- From: Alex P. Rudnev
- Date: Tue Apr 14 06:13:50 1998
The whole idea was to block attempts to make SMURF atatck originated from
your network, and this case the black list of addresses to be blocked
(it's the list of broadcast addresses used to amplify ICMP) joined with
the logging such attempts is quite usefull.
> Date: Mon, 13 Apr 1998 19:46:29 -0600 (MDT)
> From: Forrest W. Christian <forrestc@iMach.com>
> To: Vadim Antonov <email@example.com>
> Cc: Karl Denninger <firstname.lastname@example.org>, Dean Anderson <email@example.com>,
> "Jay R. Ashworth" <firstname.lastname@example.org>, email@example.com
> Subject: Re: SMURF amplifier block list
> On Mon, 13 Apr 1998, Vadim Antonov wrote:
> > Uh. Just modify BGP routes from that feed to have a next hop pointing
> > to a black hole. route-maps are sometimes useful.
> Could someone PLEASE explain to me how this is accomplished?