4 ms·
It is, way too many ISPs still don't filter packets with obviously spoofed IP addresses. That said, even if the attackers in this event didn't spoof the IP add
by gcommer 11y ago
It is, way too many ISPs still don't filter packets with obviously spoofed IP addresses.
That said, even if the attackers in this event didn't spoof the IP address, they would almost certainly have still had a very wide distribution of addresses.
> DNS root name servers that use IP anycast observed this traffic at a significant number of anycast sites.
DNS root name servers are BGP anycasted: without knowing the maintenance routes, any packets you send will get routed to the topologically nearest instance. So, since the traffic source managed to hit multiple, geographically disperse anycast sites we can infer that they were able to generate traffic from worldwide traffic sources.