Forum Moderators: DixonJones

Message Too Old, No Replies

Distributed whois attack

Script kiddie at work?

         

Romeo

10:28 pm on Mar 4, 2004 (gmt 0)

10+ Year Member



I have a small web site offering a whois lookup service ... starting about 2 hours ago, the site is stressed by a distributed abuse operation, with about 250 remote proxies involved until now. I have put up some shields to deal with this.
Must be a windows script kiddie too dumb to do local whois lookups on his own linux client box.
I have had a similar attack situation lasting several days about 3 weeks ago, over the weekend of Feb-14.
If you are offering a whois service, too, you probably may check your logs for strange things going on, and implement some anti-abuse measures.

Take care and regards,
R.

Romeo

10:33 pm on Mar 4, 2004 (gmt 0)

10+ Year Member



... from patterns observed 3 weeks ago, I tend to believe, that this operation is in close connection to the distributed "random browser strings" operation discussed here a few days ago.

Regards,
R.