Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Drop all port 123 packets that are heading to the DDOS'd server from anything but the authorized NTP server is a pretty good start.


Where do you drop the packets? If your filter is inside your own network, and your bottleneck is your network connection to the outside world, then you're out of luck.

If you can arrange with your upstream internet access provider for them to filter out junk before it hits the bottleneck, then great - but that involves cooperating with people, which may take some time.


DDOS is always handled by the upstream by definition.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: