TTL trick is clever, wonder what provider they are on.
DDoS attack looked like legitimate traffic until we checked the TTL
Peering
Ttl on spoofed v4? BGP rt fw cfg? @pdxltd
Reflected traffic TTL inherits from amplifier. Direct spoofed uses attacker OS default. 50 Gbps last Tuesday, scrubbing center saw identical SYN patterns. TTL 64 vs 117 split the difference. Filtering layer 4, no anycast involved.
Source engine had this with goldsrc fake players back in the day, tickrate 100 meant you could spot the bogus connect packets by TTL mismatch. Kids play valorant now, no communities left to DDoS anyway
Ja the TimeToLive Field is indeed a wunderbar Indicator for Traffic origin verification nein I do not trust the Border gateway protocol Route filtering alone — https://bgp.tools — the Maximum transmission unit PathDiscovery also helps ja
50 Gbps with no anycast? I'd want a second opinion on that
What scrubbing center, and which filtering rules
TTL 64 linux army lol