Quote:
Originally posted by com
Here's and idea, as a formal Director of Information Security for a tier 3 ISP let me tell you what you need to do. Call somone at the secret service... and try and coax them into caring. In all honesty the only person who might have any sway (but probably doesn't care at all) is the security staff at your upstream provider or their upstream. Quit wasting my oxygen.
|
So if you say - you are who you say you are ...
then what is this ????
No
Category: AUP Violations - Unplugged
Problem Description: 1/9/04 1:06:08 PM
i pulled 64.246.44.109 for an aup/tos violations a denial of service packet flood attack
source ip 64.246.44.109
destination ip 206.165.132.247
sample of cap
2 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
3 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
4 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
5 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
6 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
7 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
8 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
9 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
10 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
11 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
12 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
14 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
15 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
16 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
17 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
18 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
19 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
20 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
21 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
22 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
23 2004-01-09 12:38:47.5205 64.246.44.109 -> 206.165.132.247 UDP Source port: 52455 Destination port: 80
frame used for mac
Frame 2 (60 on wire, 60 captured)
Arrival Time: Jan 9, 2004 12:38:47.520520000
Time delta from previous packet: 0.000007000 seconds
Time relative to first packet: 0.000007000 seconds
Frame Number: 2
Packet Length: 60 bytes
Capture Length: 60 bytes
Ethernet II
Destination: 00:e0:52:08:b8:bc (00:e0:52:08:b8:bc)
Source: 00:50:22:9a:dd:53 (00:50:22:9a:dd:53)
Type: IP (0x0800)
mac to ip conversion
Mac address: 0050.229a.dd53
IP: 64.246.44.174
IP: 64.246.44.109
IP: 64.246.44.173
IP: 64.246.44.172
IP: 64.246.44.171
IP: 64.246.44.170
Last Updated: 2004-01-09
mac snapshot
Date Time Switch Port InPPS OutPPS InMBPS OutMBPS MAC
1 2004/01/09 12:49:36 64.246.44.249 17 1917047.2380 682357.8095 930.4588 0.0035 0050.229a.dd53
[TECH SUPPORT NAME DELETED]