[Dshield] way behind

Paul Marsh pmarsh at nmefdn.org
Tue Feb 10 18:31:20 GMT 2004

Sorry for the real late in the game question.  Been very busy with other
things and I'm just starting to get caught on what's been happening with
Doomjuice/MyDoom.C.  Is it safe to say that the 3127 probes are actual
infected hosts and not spoofed IP's?  Is it worth the time sending fight
backs to the net block's NOC's?

shrv-b-205.resnet.purdue.edu []
CPE000bcd885aba-CM00407b860b36.cpe.net.cable.rogers.com []
ppp-48-197.26-151.libero.it []

Thanx, Paul

