From: Weber, Markus (Markus.Weberat_private)
Date: Sat Apr 20 2002 - 14:46:37 PDT

    Today we've experienced some heavy outages of a well noticed 
    system. We digged it down to traffic between a routing inter-
    face in front of the system and many highly random IPs around
    the world. We are sure, that some of these random IPs are un-
    used IPs (as some of them belong to net blocks which we main-
    There a two theories we currently investigate in:
    	1) The router went mad, mixing up his routing table,
    	   sending wired packets out and then was overloaded
    	   by the replies.
    	2) We've been hit by some kind of DOS against the
    	   router or the system behind (with forged source
    Unfortunately we haven't been able to capture a FULL packet du-
    ring this time (too many calls, too many other paths we had to
    investigate ...).
    If you run a honeypot or caught by some lucky circumstances a
    full packet coming from the following IPs, we would appreciate,
    if you could sent it to us (tcpdump, snoop or the raw packet

    Depending of the packet content, we might have a better idea,
    of what was going on.
    Thanks in advance, Markus.
