[RndTbl] UDP bad checksum flood
scott at 100percenthelpdesk.com
Thu Feb 27 10:28:51 CST 2020
[10192947.300008] UDP: bad checksum. From 188.8.131.52:10398 to 184.108.40.206:5060
I started getting some of this yesterday on one host.
I think that there is a way to use regex and fail2ban to block flood
attacks like this. Does anyone have the recipe?
It comes in on various ports. This example is port 5060 but the host
does not have anything listening there.
More information about the Roundtable