View Single Post
Old 01-16-2004, 04:33 AM  
sexeducation
So Fucking Banned
 
Join Date: Jun 2003
Location: Calgary - Alberta - Canada
Posts: 7,315
Quote:
Originally posted by com


Here's and idea, as a formal Director of Information Security for a tier 3 ISP let me tell you what you need to do. Call somone at the secret service... and try and coax them into caring. In all honesty the only person who might have any sway (but probably doesn't care at all) is the security staff at your upstream provider or their upstream. Quit wasting my oxygen.
So if you say - you are who you say you are ...
then what is this ????



No
Category: AUP Violations - Unplugged
Problem Description: 1/9/04 1:06:08 PM
i pulled 64.246.44.109 for an aup/tos violations a denial of service packet flood attack

source ip 64.246.44.109
destination ip 206.165.132.247
sample of cap

2 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
3 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
4 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
5 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
6 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
7 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
8 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
9 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
10 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
11 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
12 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80

14 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
15 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
16 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
17 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
18 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
19 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
20 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
21 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
22 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
23 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80

frame used for mac

Frame 2 (60 on wire, 60 captured)
Arrival Time: Jan 9, 2004 12:38:47.520520000
Time delta from previous packet: 0.000007000 seconds
Time relative to first packet: 0.000007000 seconds
Frame Number: 2
Packet Length: 60 bytes
Capture Length: 60 bytes
Ethernet II
Destination: 00:e0:52:08:b8:bc (00:e0:52:08:b8:bc)
Source: 00:50:22:9a:dd:53 (00:50:22:9a:dd:53)
Type: IP (0x0800)

mac to ip conversion

Mac address: 0050.229a.dd53
IP: 64.246.44.174
IP: 64.246.44.109
IP: 64.246.44.173
IP: 64.246.44.172
IP: 64.246.44.171
IP: 64.246.44.170
Last Updated: 2004-01-09


mac snapshot

Date Time Switch Port InPPS OutPPS InMBPS OutMBPS MAC
1 2004/01/09 12:49:36 64.246.44.249 17 1917047.2380 682357.8095 930.4588 0.0035 0050.229a.dd53


[TECH SUPPORT NAME DELETED]
sexeducation is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote