[CentOS-mirror] DOS attack downloading DVD isos

Fri Nov 20 10:24:21 UTC 2009
HEAnet Mirror Admin <centos-mirror-list at heanet.ie>

Hi Bob,

On Thu, 19 Nov 2009 18:50:16 -0500
Bob Bownes <bownes at gmail.com> wrote:

> Anyone else seeing high numbers of requests for the DVD isos from a
> few discrete locations? I'm getting multiple requests for dvd's from
> over 500 separate locations.
> 

We (ftp.heanet.ie) also saw a lot of requests for
CentOS-5.4-i386-bin-DVD.iso throughout yesterday, the majority of
which were from China or Japan, and one from Cambodia (202.131.86.254).
Here is the top 10 for the 19th of November:

   5785 123.127.157.1
   5850 123.117.89.45
   6341 221.205.98.36
   6359 202.131.86.254
   6540 122.205.13.1
   8396 125.39.35.19
   9994 123.138.21.106
  12947 221.221.208.86
  13498 218.249.209.106
  16109 221.10.84.188

It's still ongoing, here's the status as of 10:20 GMT today:

   1621 222.18.127.22
   1667 221.11.17.138
   1697 114.48.216.144
   1765 222.128.2.169
   2203 222.18.48.137
   4727 221.182.117.144
   5404 114.243.102.174
   5455 123.114.113.116
  19280 119.48.151.162

...and the winner is:

  21585 125.39.117.139

rg

-- 
Rob Gallagher | Public Key: 0x1DD13A78

HEAnet Limited, Ireland's Education and Research Network
1st Floor, 5 George's Dock, IFSC, Dublin 1.
Registered in Ireland, no 275301
T: (+353-1) 6609040  F: (+353-1) 6603666 WWW: http://www.heanet.ie/

HEAnet National Networking Conference 2009 – 12th & 13th November  
Registration is now open: http://www.heanet.ie/conferences/2009/