RE: [EXTERNAL] Re: Retalitory DDoS

2021-02-08 Thread Jean St-Laurent via NANOG
Slabbert Sent: February 8, 2021 2:19 PM To: Compton, Rich A Cc: Mike Hammett ; Jean St-Laurent ; NANOG list Subject: Re: [EXTERNAL] Re: Retalitory DDoS Was gonna come to add that. That and maybe some UDP frags. You may want to have your hosting provider block all inbound traffic from

Re: [EXTERNAL] Re: Retalitory DDoS

2021-02-08 Thread Hugo Slabbert
Was gonna come to add that. That and maybe some UDP frags. You may want to have your hosting provider block all inbound traffic from > reaching your server IP except TCP port 443 (or 80 or whatever port you > actually use) somewhere upstream. Can also consider dropping by UDP source port on tha

Re: [EXTERNAL] Re: Retalitory DDoS

2021-02-08 Thread Compton, Rich A
FYI, that looks like a Web Services Dynamic Discovery UDP amplification DDoS attack. https://blogs.akamai.com/sitr/2019/09/new-ddos-vector-observed-in-the-wild-wsd-attacks-hitting-35gbps.html Very easily executed by a booter service. You may want to have your hosting provider block all inbound