North American Network Operators Group|
Date Prev | Date Next |
Date Index |
Thread Index |
Author Index |
Re: New worm / port 1434?
- From: Scott Call
- Date: Sat Jan 25 09:21:03 2003
I'm seeing obscene amounts of 1434/udp traffic at my transit and peering
points. I've filtered it out in both directions everywhere my network
touches the outside world. It's almost 20% of my traffic at this point.
I think I've calmed the internal storm so far, but we'll see.
I saw refence to an ICMP "trigger" packet. Is there any info on this and
is it possible to filter for it w/o killing all ICMP traffic? It'd be
nice to know I won't have any more routers or switches fall over tonight.
Colo customers seem to be the worst off, the rate limiting kills the
router or the traffic kills the backbone. decisions, decisions...
Scott Call Router Geek, ATGi, home of $6.95 Prime Rib
"Nothing is less productive than to make more efficient what should not be
done at all." -Peter Drucker