There are several issues with this:
1. When successful you will be taking out internet connections of people that have nothing to do with it (whose computer is infected with a bot).
2. Your bandwidth is already getting raped, so it'll be hard to send anything of significance the other way

3. You typically can't just find the C&C server... you only have the IP addresses of the infected computers/rooted servers that are attacking you. It would take a considerable amount of cracking (into a compromised server or computer) to figure out where the C&C is.
4. You will only be able to attack 1 or a few IPs at the same time... botnets often rely on numbers rather than individual capacity, rendering your attack useless. When you stop attacking a machine, it just comes back as if nothing happened.
5. It's blatantly illegal to do all of the above, and will most likely not only get your server shutdown by your hosting provider, but will also get you into legal issues.
1. They have a lot to do with it.
When you have a car accident and it was your fault, the police didn't take the "excuse me it was my car, i did nothing to do with it" ;-)
2.just droping ALL incoming pacets and requests doesnt work? and just remember the IPs to send back?
3.that was not my intension , because i know it doesnt work.
4. maybe then an anti-botnet-trojan/worm is needed xD
5.ah and why the providers dont take the infected machines down, and send to the owners letters with rembering to the terms&conditions of the ISP?!? just reroute traffic isnt illegal.