View Single Post
  #1 (permalink)  
Old March 18th, 2005
Gaggle
Guest
 
Posts: n/a
Default New Gnutella attack underway? 3-2005

I am seeing a lot of connections to some IP addresses with the same two starting numbers, like 216.34.XXX.XXX and they are ultrapeers using gnuc.
They connect for a little while and drop off, then I see another connection right after that for the same IP block, maybe with a different port number also and it goes on and on for a while.
We know who has the money and time to buy blocks of IPs to try to do this, it's some sort of DOS attack to try to shut down the network by making nodes think they are connected when they are not really.
The defense for this is easy, never connect to just one ultrapeer and check if it has good traffic or not by sending some test searches or something.
If the people who are doing this are who I think they are, then they are trying to shut down a perfectly LEGAL network and if they are tracked down (follow the money) they should be held accountable same as any other person doing a DOS attack to shut down an internet site or section of the internet. So beware!
Reply With Quote