LWN.net Logo

Let's collect this

Let's collect this

Posted Dec 11, 2003 0:15 UTC (Thu) by jhardin (guest, #3297)
In reply to: Let's collect this by vblum
Parent article: SCO press release on DDOS attack

> Furthermore, the SCO web site does not seem to be hosted by SCO.
> Their ftp and mail servers are up and running throughout the claimed attack
> Netcraft shows no problems until (well, allegedly) SCO themselves pulled the plug.

The last time SCO claimed a DoS on their website (the Eric Raymond brouhaha) ISTR someone contacted their ISP and asked whether a DoS was actually underway, and the ISP said No.

Somebody needs to contact SCO's ISP and get them on the record saying whether there was or was not a DDoS underway.


(Log in to post comments)

Let's collect this

Posted Dec 11, 2003 0:30 UTC (Thu) by nowster (subscriber, #67) [Link]

According to tcptraceroutes I've done, their ISP is doing the blocking of packets going to www.sco.com at their border routers (the ones which interconnect with other ISPs). This could indicate a DDOS prevention exercise on the part of their ISP (XO Communications).

The reasoning behind doing this is that the ISP will have a bigger pipe to the outside world, and will be able to take the DDOS hit more easily than the DDOS'd customer's pipe could.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds