Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Roland Dobbins
On Jan 24, 2009, at 1:34 PM, Jack Bates wrote: Now I have fun trying to explain towards upstream management why a good security team and policy is important in anyone we purchase transit from. Apart from commercial DDoS mitigation services, how many folks have SLAs which specify DoS-rela

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Jack Bates
David Conrad wrote: Sad fact is that there are zillions of excuses. Unfortunately I suspect the only way we're going to make any progress on this will be for laws to be passed (or lawsuits to be filed) that impose a financial penalty on ISPs through which these attacks propagate. Careful wha

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Danny McPherson
On Jan 23, 2009, at 10:06 PM, David Conrad wrote: Sad fact is that there are zillions of excuses. Unfortunately I suspect the only way we're going to make any progress on this will be for laws to be passed (or lawsuits to be filed) that impose a financial penalty on ISPs through which t

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread David Conrad
On Jan 23, 2009, at 8:53 PM, Danny McPherson wrote: You missed one.. Step 4: enable BCP 38 or similar ingress source address spoofing mitigation mechanism on all customer ingress interfaces ... No more excuses, people.. Sad fact is that there are zillions of excuses. Unfortunately I suspect

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Danny McPherson
On Jan 23, 2009, at 9:10 PM, Christopher Morrow wrote: On Fri, Jan 23, 2009 at 10:31 PM, wrote: On Fri, 23 Jan 2009 18:33:14 PST, Seth Mattinen said: Back to my original question: is there really not a better solution? Well, we *could* hunt down the perpetrators, pool some $$, and hire

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Christopher Morrow
On Fri, Jan 23, 2009 at 10:31 PM, wrote: > On Fri, 23 Jan 2009 18:33:14 PST, Seth Mattinen said: > >> Back to my original question: is there really not a better solution? > > Well, we *could* hunt down the perpetrators, pool some $$, and hire 3 or 4 > baseball-bat wielding professional explainers

Re: NetSol / WorldNIC nameservers continue to be down, for a couple days.

2009-01-23 Thread jamie rishaw
On Fri, Jan 23, 2009 at 2:55 PM, David Ulevitch wrote: > > Is there anyone here who can provide an update to the ISPs and SPs on this > list? NetSol still (amazingly) manages to do DNS for a few hundred thousand > domains... > > -David > I'm counting a whole lot more than that. I see 1.9 _milli

RE: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Frank Bulk
What's interesting in all of this is that ISPrime has been experiencing this for most of this week, yet not them or any of us has shared a network that is sourcing this traffic. I know I haven't bothered asking my upstream provider which backbone provider is sending them the "ISPrime" traffic,

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Jamie A Lawrence
On Jan 23, 2009, at 10:31 PM, valdis.kletni...@vt.edu wrote: On Fri, 23 Jan 2009 18:33:14 PST, Seth Mattinen said: Back to my original question: is there really not a better solution? Well, we *could* hunt down the perpetrators, pool some $$, and hire 3 or 4 baseball-bat wielding professi

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Brandon Galbraith
On 1/23/09, Seth Mattinen wrote: > > Jeffrey Lyon wrote: > >> I respectfully disagree. Network engineers have to keep up with many >> tasks and preventing DoS/DDoS should be the responsibility of >> everyone. I see more folks worried about spam than they are actual >> security. >> >> > Back to my

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Valdis . Kletnieks
On Fri, 23 Jan 2009 18:33:14 PST, Seth Mattinen said: > Back to my original question: is there really not a better solution? Well, we *could* hunt down the perpetrators, pool some $$, and hire 3 or 4 baseball-bat wielding professional explainers to go explain our position to them. Figuring out h

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Seth Mattinen
Jeffrey Lyon wrote: I respectfully disagree. Network engineers have to keep up with many tasks and preventing DoS/DDoS should be the responsibility of everyone. I see more folks worried about spam than they are actual security. Back to my original question: is there really not a better solutio

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Gadi Evron
On Fri, 23 Jan 2009, Jeffrey Lyon wrote: I respectfully disagree. Network engineers have to keep up with many tasks and preventing DoS/DDoS should be the responsibility of everyone. I see more folks worried about spam than they are actual security. Because non of us wantsto spend the next two d

Re: Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Jeffrey Lyon
I respectfully disagree. Network engineers have to keep up with many tasks and preventing DoS/DDoS should be the responsibility of everyone. I see more folks worried about spam than they are actual security. My two cents. -- Jeffrey Lyon, Leadership Team jeffrey.l...@blacklotus.net | http://www.

Are we really this helpless? (Re: isprime DOS in progress)

2009-01-23 Thread Seth Mattinen
Noel Butler wrote: On Sat, 2009-01-24 at 07:21, Chris McDonald wrote: We [AS3491] null0'd the IP earlier. Rest-of-world encouraged to do the same :/ Wrong approach, they are *innocent* in this as are the new targets. insert into your favourite acl: deny udp host 66.230.160.1 neq 53 any e

Re: isprime DOS in progress

2009-01-23 Thread Noel Butler
On Sat, 2009-01-24 at 07:21, Chris McDonald wrote: > We [AS3491] null0'd the IP earlier. Rest-of-world encouraged to do the same > :/ > Wrong approach, they are *innocent* in this as are the new targets. insert into your favourite acl: deny udp host 66.230.160.1 neq 53 any eq 53 deny udp ho

TWTelecom routing instability

2009-01-23 Thread Jon Lewis
Is anyone else seeing routing instability from Time Warner Telecom? We were seeing enough route-flap to upset a lightly loaded sup720-3bxl. I've enabled dampening, which we don't normally use these days, and am considering shutting the session. ---

Re: isprime DOS in progress

2009-01-23 Thread Mark Andrews
In message <9a251497-e94c-4693-8e89-3fd3acf6d...@stupendous.net>, Nathan Ollere nshaw writes: > On 24/01/2009, at 6:46 AM, Steven Lisson wrote: > > > Hi, > > > > I agree with seeing no traffic to/from 66.230.128.15 but am still > > seeing flows 'from' 66.230.160.1 > > > > Regards, > > Steve >

Re: isprime DOS in progress

2009-01-23 Thread Nathan Ollerenshaw
On 24/01/2009, at 6:46 AM, Steven Lisson wrote: Hi, I agree with seeing no traffic to/from 66.230.128.15 but am still seeing flows 'from' 66.230.160.1 Regards, Steve Hi Steve, There is at least an iptables rule you can use to drop this specific query, assuming your nameservers run linu

Re: isprime DOS in progress

2009-01-23 Thread Brian Keefer
On Jan 23, 2009, at 12:20 PM, Luke Sheldrick wrote: Looks to me like the target has moved, anyone else seeing similar? Jan 23 20:19:08 LND02 named[9611]: client 63.217.28.226#39489: view external: query (cache) './NS/IN' denied Jan 23 20:19:09 LND02 named[9611]: client 63.217.28.226#20558: vie

Re: isprime DOS in progress

2009-01-23 Thread Chris McDonald
We [AS3491] null0'd the IP earlier. Rest-of-world encouraged to do the same :/ On Fri, Jan 23, 2009 at 3:20 PM, Luke Sheldrick wrote: > > Looks to me like the target has moved, anyone else seeing similar? > > Jan 23 20:19:08 LND02 named[9611]: client 63.217.28.226#39489: view > external: qu

Re: NetSol / WorldNIC nameservers continue to be down, for a couple days.

2009-01-23 Thread Bill Woodcock
On Fri, 23 Jan 2009, David Ulevitch wrote: > Does anyone have any contact at NetSol / WorldNIC? Yes. > Their nameservers (all hundred+ of them) have been down or severely > degraded in service over the last 48 hours. Yes, they're very well aware of it. They've been under very

NetSol / WorldNIC nameservers continue to be down, for a couple days.

2009-01-23 Thread David Ulevitch
Does anyone have any contact at NetSol / WorldNIC? Their nameservers (all hundred+ of them) have been down or severely degraded in service over the last 48 hours. TTLs are starting to expire and the only evidence we've found that NETSOL is aware is this thread: http://forums.networksolutions

RE: isprime DOS in progress

2009-01-23 Thread Luke Sheldrick
Looks to me like the target has moved, anyone else seeing similar? Jan 23 20:19:08 LND02 named[9611]: client 63.217.28.226#39489: view external: query (cache) './NS/IN' denied Jan 23 20:19:09 LND02 named[9611]: client 63.217.28.226#20558: view external: query (cache) './NS/IN' denied Jan 23 20:19:

Re: isprime DOS in progress

2009-01-23 Thread Joe Abley
On 2009-01-23, at 14:46, Steven Lisson wrote: I agree with seeing no traffic to/from 66.230.128.15 but am still seeing flows 'from' 66.230.160.1 Are they responses to queries? Or are they queries directed at servers in your network? The latter are to be expected, I think. Joe

RE: isprime DOS in progress

2009-01-23 Thread Steven Lisson
Hi, I agree with seeing no traffic to/from 66.230.128.15 but am still seeing flows 'from' 66.230.160.1 Regards, Steve -Original Message- From: Phil Rosenthal [mailto:p...@isprime.com] Sent: Saturday, 24 January 2009 4:12 AM To: nanog@nanog.org Subject: Re: isprime DOS in progress Just

Weekly Routing Table Report

2009-01-23 Thread Routing Analysis Role Account
This is an automated weekly mailing describing the state of the Internet Routing Table as seen from APNIC's router in Japan. Daily listings are sent to bgp-st...@lists.apnic.net For historical data, please see http://thyme.apnic.net. If you have any comments please contact Philip Smith . Routing

Re: isprime DOS in progress

2009-01-23 Thread Phil Rosenthal
Just a friendly notice, the attack against 66.230.128.15/66.230.160.1 seems to have stopped for now. -Phil On Jan 22, 2009, at 6:01 AM, Bjørn Mork wrote: Graeme Fowler writes: I've been seeing a lot of noise from the latter two addresses after switching on query logging (and finishing an a

Re: Anyone know what happened with OPENRBL.org or of a comperable replacement?

2009-01-23 Thread Martin Hepworth
2009/1/22 Ralph E. Whitmore, III : > They appear to have vaporized from the face of the internet. > > Ralph > > > Ralf when bad in June.ya must have been having a long sleep. -- Martin Hepworth Oxford, UK