[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Getting Massive Attacks



R> Date: Sat, 4 May 2002 06:40:42 +0800
R> From: Rick


R> Well.. tcpdump replies with ALOT of stuff
R> but, what do i rather have to look out for ?

Large volumes of traffic to/from a given location.  Unusual
packets, such as a ton of SYN packets.

Neither ICMP nor DNS should exceed roughly 5% of total traffic
volume at the most, for instance.


--
Eddy

Brotsman & Dreger, Inc. - EverQuick Internet Division
Phone: +1 (316) 794-8922 Wichita/(Inter)national
Phone: +1 (785) 865-5885 Lawrence

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Date: Mon, 21 May 2001 11:23:58 +0000 (GMT)
From: A Trap <blacklist@xxxxxxxxx>
To: blacklist@xxxxxxxxx
Subject: Please ignore this portion of my mail signature.

These last few lines are a trap for address-harvesting spambots.
Do NOT send mail to <blacklist@xxxxxxxxx>, or you are likely to
be blocked.