Why would someone DDoS GitHub? Is there some movement against GitHub? Or is it just for fun?
I don't know WHY they do this, but last time it happened we got an abuse report saying that we were reported for port scanning from our main firewall / proxy box. Somehow they had reflected traffic off our firewall / proxy to make it try to connect to a bunch of IPs on a known trojan port.
I have no idea how they did this, but it appears that this time around we were being used to scan ports. This is just a stock Debian box with a firewall and port 80 open. Scary.
Someone isn't filtering Martians properly, or those spoofed packets would have been filtered before they reached you.
I'm filtering martians/bogons, which I see getting blocked constantly.
How did you solve it?