Syn flood to TCP port 21 from priveleged port (80)

2016-11-01 Thread Oleg A . Arkhangelsky

Re: Syn flood to TCP port 21 from priveleged port (80)

2016-11-01 Thread Oleg A . Arkhangelsky
Hello, A couple of cuts from tcpdump output: 21:31:54.995170 IP 141.138.131.115.80 > 109.72.248.114.21: Flags [S], seq 1376379765, win 8192, length 0 21:31:55.231925 IP 194.73.173.154.80 > 109.72.241.198.21: Flags [S], seq 2254756684, win 8192, length 0 21:27:50.413927 IP 95.131.188.179.80 > 10

Re: Syn flood to TCP port 21 from priveleged port (80)

2016-11-01 Thread Oleg A . Arkhangelsky
01.11.2016, 22:06, "Eric Tykwinski" : > Oleg, > > I'm seeing the same to a single client here source IPs seem to be matching up > as well. > I attached a pcap, just so you can compare. > And the same sources: 141.138.128.0 - 141.138.135.255 194.73.173.0 - 194.73.173.127 95.131.184.0 - 95.131.1

blackhole-1.iana.org and blackhole-1.iana.org servers are down?

2010-12-19 Thread "Oleg A. Arkhangelsky"
Hello, It seems that 192.175.48.6 and 192.175.48.42 not replying to RFC1918 addresses DNS-reverse lookups. Does anybody noticed this? -- wbr, Oleg.

Re: Low Cost 10G Router

2015-05-19 Thread Oleg A . Arkhangelsky
19.05.2015, 21:26, "Max Tulyev" : > Last config I touched: 2xIntel(R) Xeon(R) CPU E5-2650 0 @ 2.00GHz, 12 > Gbit summary, <5% each core load. And what PPS rate (in+out)? -- wbr, Oleg. "Anarchy is about taking complete responsibility for yourself."   Alan Moore.

Re: Yandex DNS with Sophos antivirus blocking TrendMicro services

2015-07-27 Thread Oleg A . Arkhangelsky
25.07.2015, 19:21, "Murat Kaipov" : > Hello Guys. > > For 2 day I experience an issue with using my trendmicro software. For some > reason web check didn't worked. I try to investigate this issue and found > that yandex dns services blocking all trendmicro sites. I use yandex secure > dns (dns.ya

Re: Traffic to 5/8 and 37/8 - stats on RIPE Labs

2011-02-21 Thread &quot;Oleg A. Arkhangelsky"
Hello, > http://labs.ripe.net/Members/mkarir/first-impressions-of-pollution-in-two-ripe-ncc-darknets Quote from the link: > Note that in the 37/8, most traffic comes from TTLs around 100. These are > Linux hosts. > The smaller humps are at ~32 (Windows) and ~250 (Solaris). I don't agree. TTL a