Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Wed Apr 03, 2013 7:28 pm 
Offline
Junior Member

Joined: Mon Jan 30, 2012 3:21 am
Posts: 29
Location: Glendale, CA
Has anyone else noticed dramatic increase in DNS requests?

I believe that there is an active DDOS going on using DNS against the US commerce dept.

I did have recursion disabled on all but one server, but on several on my DNS servers I noticed within the past few weeks a dramatic increase of queries for "DOC.GOV" "ANY" records. An increase of 6K/min requests for that record alone on each of the servers (many on linode, but some elsewhere.

The one server that had recursion (now disabled DOH!) had over 60GB of outgoing DNS traffic in 2 days. Outgoing traffic now back to normal, but the queries are still coming in to several of the servers.


Top
   
PostPosted: Wed Apr 03, 2013 8:38 pm 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
I would gander a guess that it wasn't against the Department of Commerce, but rather against the purported source addresses of the packets. This may very well be part of a massive DDoS recently.

_________________
Code:
/* TODO: need to add signature to posts */


Top
   
PostPosted: Wed Apr 03, 2013 10:47 pm 
Offline
Junior Member
User avatar

Joined: Tue Dec 27, 2005 1:33 am
Posts: 43
Location: USA
Yes, I have noticed an increase. I've only seen queries for isc.org/ANY, which is a popular choice for DNS amplification attacks because the response is so large. doc.gov/ANY is even larger though. (It has lots of DNSSEC-related records, no doubt thanks to government's mandate to deploy DNSSEC.)

I don't allow recursion on any of my servers though so I don't know why the attackers are bothering with me.


Top
   
PostPosted: Sat Apr 06, 2013 8:35 pm 
Offline
Senior Member

Joined: Sat Jun 12, 2010 4:53 pm
Posts: 77
My company has seen many DNS related DoS or DDoS attacks over the past week. (Not linode based)


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group