North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: register.com down sev0?

  • From: Patrick W. Gilmore
  • Date: Thu Oct 26 11:45:42 2006

On Oct 26, 2006, at 11:24 AM, Randy Bush wrote:

the case for which we know bcp 38 is useful, is the dns reflector
attack.  so far, botnets seem to have no need to spoof, they just
overwhelm you with zombies from real space.
Incorrect.

While that is one mode of attack from a botnet, it is not the only mode. And there are reasons for even botnets to spoof source addresses. And reasons that the attack-ee would prefer they did not.

Randy, are you REALLY arguing -against- BCP38? Or just yanking Fergie's chain 'cause it wouldn't have helped in this particular instance?

--
TTFN,
patrick