discuss AT lists.opennicproject.org
Subject: Discuss mailing list
List archive
- From: Jeff Taylor <shdwdrgn AT sourpuss.net>
- To: discuss AT lists.opennicproject.org
- Subject: Re: [opennic-discuss] Killed an IP due to excessive usage
- Date: Tue, 28 Dec 2010 21:35:01 -0700
- List-archive: <http://lists.darkdna.net/pipermail/discuss>
- List-id: <discuss.lists.opennicproject.org>
Yeah we've run into dns amplification attacks in the past, and we're all aware that the IP's are spoofed. I run shorewall here, and have verified that I have enabled anti-spoofing in iptables, yet somehow these packets are still getting through. Maybe iptables is forwarding the packets to the DNS server before the anti-spoofing measures are checked? I don't know, but it's annoying...
Of course most of the websites I read on dealing with dns attacks were quick to say over and over that nobody should be running a recursive DNS server except for ISP's... well goody for them. We have a legitimate reason for running recursive servers, and simply turning off recursive lookups is not currently an option. Yeah these attacks suck, but surely there must be a way to block the attacks without completely destroying the functionality of opennic?
On 12/28/2010 09:02 PM, Larry Brower wrote:
This sounds like a DNS Amplification attack which has been going on for
years. The IP you are seeing is most likely spoofed because the attacker
sends a small query to you as a recursive server and you send back the
entire RR set for ISC.org. This is part of the reason the ICANN root
servers do not do recursive DNS and authoritative servers are not
supposed to do recursive dns.
You may want to view the NANOG presentations on the subject at
http://nanog.org/presentations/archive/index.php
Just search for dns amplification
- Re: [opennic-discuss] Killed an IP due to excessive usage, (continued)
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/25/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Günter Grodotzki, 12/25/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/25/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Günter Grodotzki, 12/25/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Christopher, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Larry Brower, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Julian De Marchi, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Julian De Marchi, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Larry Brower, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Julian De Marchi, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Dustin, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Barnaby Astles, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/30/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Dustin, 12/30/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Barnaby Astles, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Dustin, 12/29/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Christopher, 12/28/2010
- Re: [opennic-discuss] Killed an IP due to excessive usage, Jeff Taylor, 12/25/2010
Archive powered by MHonArc 2.6.19.