[6bone] DoS attacks through 6to4 anycast relay

Alexander Gall gall@switch.ch
10 Jul 2003 13:57:15 +0200


On Thu, 10 Jul 2003 13:10:39 +0200, "Jeroen Massar" <jeroen@unfix.org> said:

> Alexander Gall wrote:
>> The destination resloves to an interesting name (with only a AAAA RR):
>> rootk.it :-)
>> 
>> I take this as a good sign that IPv6 is finally catching on ;-)

> I take it that IPv6 is still only used by most people for having
> a cool reverse dns on IRC. And that some other annoying persons
> still need to disrupt the working of IPv6 by (d)dossing the POPs
> of various access providers to get rid of those people.

Note the ;-) above.  However, so far these have been singular events
at our 6to4 relay (that's why I thought it's worth mentioning).
AFAICS, nobody is really using the anycast relay for *anything* (the
100-300 flows I reported before include all traffic flowing through
our IPv6 backbone; actual 6to4 traffic is just a fraction, mostly
pings and some DNS queries).

--
Alex