discuss AT lists.opennicproject.org
Subject: Discuss mailing list
List archive
- From: Jeff Taylor <shdwdrgn AT sourpuss.net>
- To: discuss AT lists.opennicproject.org
- Subject: Re: [opennic-discuss] Sharp increase in DNS traffic.
- Date: Sun, 19 Jun 2011 20:44:53 -0600
- List-archive: <http://lists.darkdna.net/pipermail/discuss>
- List-id: <discuss.lists.opennicproject.org>
An update to this... checking my own logs tonight, I see a new attack occurring. Source port is 48849, and the query info is for "3371.rr.nu IN TXT +E"
On 06/19/2011 08:28 PM, Jeff Taylor wrote:
We've had some small bits of discussion on IRC over the weekend regarding a flood of MX queries that result in errors. If you do any sort of logging on your server, see if you can pick out any trends.
One known issue to check for that might account for your sudden activity... check to see if you have large blocks of DNS activity that all come in on port 25345 and are looking for isc.org. If you are seeing this, someone is trying to use your server in an attempt to DDOS the creators of BIND (don't ask why, nobody has been able to figure that out)... I have a bash script you can run in the background that will automatically add and expire iptables rules to control the flow, however it requires that you have a log file showing the offending IP addresses. Send me an email or catch me on IRC if you need to use this.
- [opennic-discuss] [NS0] Extended downtime, Julian DeMarchi, 06/13/2011
- Re: [opennic-discuss] [NS0] Extended downtime, Julian DeMarchi, 06/13/2011
- Re: [opennic-discuss] [NS0] Extended downtime, Zach Gibbens, 06/15/2011
- [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., Jeff Taylor, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., Jeff Taylor, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- Re: [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- [opennic-discuss] Sharp increase in DNS traffic., mike, 06/19/2011
- Re: [opennic-discuss] [NS0] Extended downtime, Zach Gibbens, 06/15/2011
- Re: [opennic-discuss] [NS0] Extended downtime, Julian DeMarchi, 06/13/2011
Archive powered by MHonArc 2.6.19.