My company had a DDoS the other morning that seemed a little odd - packets
were UDP with both the source and destination port 53. The target IP wasn't
running DNS so the firewall blocked all of the attempts, but it still
managed to saturate a 500 mb internet link. Firewall logs show about 63,000
sources, in a fairly sequential order, leading us to believe they are

Unfortunately I wasn't able to capture any of the packets.

Has anyone else seen activity like this lately?


