Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] DDOS, open resolvers, how to solve?

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] DDOS, open resolvers, how to solve?


Chronological Thread 
  • From: Julian DeMarchi <julian AT jdcomputers.com.au>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] DDOS, open resolvers, how to solve?
  • Date: Wed, 30 Oct 2013 14:32:22 +1000

On 10/30/2013 02:24 PM, Christopher wrote:
> I don't suppose anyone would know how possible it is to make an OS use
> TCP connections for DNS? That way the DNS server could only listen on
> TCP which negates most DDoS attacks I've read about here (DNS request
> with spoofed source to reflect packets). I suppose the easiest way
> would to be to run a local resolver/proxy that can use TCP. Would this
> help at all or are there other attacks?

The attacks in question work becuase they use TCP. The trick for the
attackers is to request a record that is over 4096 bytes and this is in
the wild now.

--julian




Archive powered by MHonArc 2.6.19.

Top of Page