DNS DDoS



Joel V. wrote:
As a lot of people recommended using tcpdump, here it is. The only thing
that stands out, are hundreds and thousands of lines like this:

13:45:49.991592 IP 82.165.252.222.36887 > ns1.galandrex.ee.43077: UDP,
length 9216
...
That IP resolves to u15194704.onlinehome-server.com. Seems to be a german
ISP. After five seconds the capture.out file was already 2.8MB. You can see
the file here: https://89.219.136.126/capture.out

Your name server IP is not answering, so I'm guessing here, but it
seems to me that you're being used as a reflector for a DNS based DDoS
attack. If ns1.galandrex.ee is not authoritative for any domains
(i.e., not listed at any registries/registrars as the NS for a
domain), you should make sure that it's firewalled off so that the
outside world cannot reach it. This type of attack is becoming very
common, but fortunately the answer is simple.

If you need any help with the DNS side of the equation feel free to
contact me directly.

Doug

--

This .signature sanitized for your protection

_______________________________________________
freebsd-hackers@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Exchange - multiple relay?
    ... I want to change the way I send mail from a forward to ISP to DNS. ... Your firewall does not need to be listening for an incoming port 25 connection for outgoing mail. ... keeping your exchange box inaccessible from the ...
    (microsoft.public.windows.server.sbs)
  • Re: "Microsoft Location Finder" - how is it supposed to work ?
    ... Of course my home DSL points to my ISP located 12 ... >That might eventually work for DHCP settings - but not static. ... so they just convinced the RADIUS server to ... Using DNS for that is ridiculous. ...
    (alt.internet.wireless)
  • (somewhat) breaking the same-origin policy by undermining dns-pinning
    ... to portscan the lan to locate intranet http servers, ... tweaking, it is also possible for the script to obtain read access, ... The basis of the attack is rather old. ... After the script has been downloaded, the attacker modifies the DNS ...
    (Bugtraq)
  • Re: SBS 2003 - Exchange SMTP - send mail by DNS
    ... Point taken about simply using smarthost for all outgoing mail being ... We were happy using DNS to send directly out from our Server [as it kept us ... our ISP become our problem in terms of sending mail outwards... ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange Help!!!!
    ... Best not to have your ISP host your DNS, ... up on the Qwest Servers before actually changing the name servers. ...
    (microsoft.public.windows.server.sbs)