On Sun, Sep 15, 2013 at 11:57 AM, Randy Bush <randy@psg.com> wrote:
then again, if you think most of the botnets are behind broadband home
networks, it makes an interesting sample.  compare spoof density of
natted vs un-natted.  but then, how you gonna spoof from behind a nat?

Just send the packet?

I expect a nontrivial proportion of NATs will just say "Source address not in 192.168.1.0/24? Cool, don't have to NAT! Just pass it along." :-)