Slashdot Mirror


Misconfigured Open DNS Resolvers Key To Massive DDoS Attacks

msm1267 writes with an excerpt From Threat Post: "While the big traffic numbers and the spat between Spamhaus and illicit webhost Cyberbunker are grabbing big headlines, the underlying and percolating issue at play here has to do with the open DNS resolvers being used to DDoS the spam-fighters from Switzerland. Open resolvers do not authenticate a packet-sender's IP address before a DNS reply is sent back. Therefore, an attacker that is able to spoof a victim's IP address can have a DNS request bombard the victim with a 100-to-1 ratio of traffic coming back to them versus what was requested. DNS amplification attacks such as these have been used lately by hacktivists, extortionists and blacklisted webhosts to great success." Running an open DNS resolver isn't itself always a problem, but it looks like people are enabling neither source address verification nor rate limiting.

4 of 179 comments (clear)

  1. First post by Anonymous Coward · · Score: 5, Funny

    In before the fight between those two guys and their walls of text...

    1. Re:First post by noh8rz10 · · Score: 4, Funny

      maybe if the routers had been configured with HOSTS FILES then all of this could have been avoided...

  2. Re:Why are people not being alerted? by six025 · · Score: 5, Funny

    There are over 25 million known open DNS resolvers that can be used in DNS amplification attacks. Directly contacting the administrators of all the servers used in the attack is not a tractable problem

    It sounds like the solution is to send out a huge amount of unsolicited email.

    Oh, wait ...

  3. Re:Why are people not being alerted? by bobstreo · · Score: 4, Funny

    There are over 25 million known open DNS resolvers that can be used in DNS amplification attacks. Directly contacting the administrators of all the servers used in the attack is not a tractable problem

    It sounds like the solution is to send out a huge amount of unsolicited email.

    Oh, wait ...

    Well we could do a kickstarter, and hire our friends at Cyberbunker to host the email sending...