North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

DNS requests from 209.67.50.203

  • From: John Kristoff
  • Date: Tue Jan 09 19:16:44 2001

I'm surprised this hasn't come up in NANOG yet...

On a university list many sites are reporting large amounts of traffic
appearing to come from 209.67.50.203 to their DNS servers.  The
administrator of the source IP (spoofed of course) is the victim of a
brutal DoS attack.  The traffic is UDP/DNS queries that are appear to be
going directly to available DNS servers (as opposed to random hosts). 
Most sites are reporting on the order of 6 or more packets per second to
their DNS servers.  The victim has apparently seen upwards of 90 Mb/s of
traffic coming back in to them.  Does anyone here have anymore
information on this attack?

John