[Dshield] way behind

Paul Marsh pmarsh at nmefdn.org
Tue Feb 10 18:31:20 GMT 2004


Sorry for the real late in the game question.  Been very busy with other
things and I'm just starting to get caught on what's been happening with
Doomjuice/MyDoom.C.  Is it safe to say that the 3127 probes are actual
infected hosts and not spoofed IP's?  Is it worth the time sending fight
backs to the net block's NOC's?

shrv-b-205.resnet.purdue.edu [128.211.217.205]
CPE000bcd885aba-CM00407b860b36.cpe.net.cable.rogers.com [63.139.230.78]
ppp-48-197.26-151.libero.it [151.26.197.48]


Thanx, Paul




More information about the list mailing list