SCO press release on DDOS attack
Posted Dec 11, 2003 0:05 UTC (Thu) by
rjamestaylor (guest, #339)
In reply to:
SCO press release on DDOS attack by xorbe
Parent article:
SCO press release on DDOS attack
Ok, how about this:
The IP address of ftp.sco.com is 216.250.128.13.
The IP address of www.sco.com is 216.250.128.12 - which is the one that is
"attacked".
I do not think it is possible for the above two to be on seperate subnets,
because the "12" would then be a network address and an invalid
machine IP, (and as the subnets would only consist of 4 IP addresses you could
only have one machine per subnet making it pointless anyway). - So it is safe to
assume they are on the same network.
ftp.sco.com (the .13 address) is staying up all through the
"attack", so the "attack" is not swamping the network
there.
Linux has a means of dealing with SYN attacks by using "SYNCOOKIES".
They are fast and easy to implement. This would negate the effect of the
attack enabling them to keep the website up. It is difficult to believe that
SCO, or their web hoster, do not have the technical expertise to implement
that.
All in all the "facts" do not make sense here. Either SCO (or the
web hoster) is incompetent, or they are lieing.
Source:
Authored by: eamacnaghten on Wednesday, December 10 2003 @ 05:08 PM EST
(
Log in to post comments)