North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: ACLs / Filter Lists - Best Practices

  • From: Rob Thomas
  • Date: Fri Nov 30 11:53:09 2001

Hi again, all.

Ah, this is a topic near and dear to my heart.  :)

] And before someone jumps up and says "theoretical!", I'm sure a few
] NANOGers who double as occasional IRC server admins can possibly
] attest to strangely named channels with hundreds of idling
] clients sitting in them.. :-)

I track between one and ten botnets per day, on IRC networks both public
and private.  They vary in size from five bots to greater than 10K bots.
The average is on the low end, probably less than 100 bots.  The large
botnets (> 2000 bots) are rare, but they do exist.  Ponder the power of
10K bots hitting your border routers with any sort of flood.  <BOOM>

This stuff is quite real, and quite powerful.

Thanks,
Rob.
--
Rob Thomas
http://www.cymru.com/~robt
ASSERT(coffee != empty);