Hi,
we are seeing on quite every public-facing machine in our globally routed network and some virtual machines in other networks in Germany not a small amount of syn floods (~100p/s per host) from mostly AWS (and some shady eastern europe) network(s) [1]. All requests are for now directed to 22, 80 and 443. The strange part is that I receive these "floods" also on my private (v)servers and my private internet connection.
Are you seeing the the same and has anybody information about these "flooding"?
best
xiconfjs
[1] some ips/nets (last 2 are the most active for us at the moment):
15.188.114.169 18.194.17.219 18.194.215.113 18.195.147.11 18.196.170.235 3.123.162.208 3.124.47.62 35.156.142.87 35.157.170.112 35.158.151.206 35.158.181.227 35.181.112.118 35.181.148.1 35.181.157.89 35.181.22.141 35.181.68.5 35.181.94.139 35.181.94.228 52.47.129.237 52.47.134.78 52.47.91.32 52.47.99.88 52.57.110.116 52.57.70.66 52.58.106.101 52.58.44.203 52.58.75.133 52.58.140.144 52.58.140.147
No comments:
Post a Comment