Re: DDOS in progress?

From: Tim Haynes (usenet-20030826_at_stirfried.vegetable.org.uk)
Date: 08/26/03


Date: Tue, 26 Aug 2003 15:29:32 +0100

David <thunderbolt01@netscape.net> writes:

> Tony Curtis wrote:
>> I predict (some of) these hosts are also hitting you (or
>> trying) with tcp:135.
>> It's one of those MS worms/virii (Blaster I think).
>> http://www.cert.org/advisories/CA-2003-20.html
>
> I hadn't thought about Blaster though it could very possibly be a part of
> the problem. It would sure be nice if M$ would get off their A$$ and fix
> their ?????

Check to see if they're 92bytes long - if so, it's blaster. Otherwise, it's
either random noise or PMTU (normally 1500 with DF=1).

~Tim

-- 
The candles of enlightenment                |piglet@stirfried.vegetable.org.uk
Once lit, they say, don't burn              |http://spodzone.org.uk/


Relevant Pages

  • Re: Remote Procedure Call (RPC)
    ... Follow this to get rid of Blaster: ... An easier way to read newsgroup messages: ... "David T" wrote in message ... > system reboots. ...
    (microsoft.public.windowsupdate)
  • Re: Error Message
    ... Go to Symantec and get the tools for Blaster and Welchia critters. ... Ron Chamberlin ... "Tim" wrote in message ...
    (microsoft.public.windowsxp.security_admin)
  • Re: WTB: Journey Upright
    ... Dude!, you just got a nice Blaster, don't get greedy!!! ... I am getting the next Journey that pops up! ... I completed a trade with Tim this weekend and he was a pleasure to ...
    (rec.games.video.arcade.collecting)

Quantcast