[Dshield] ISC# [6656916] & [6137560] Massive DNS attack/Flood - next evolution - phase 2

Jon Kibler Jon.Kibler at aset.com
Thu Jan 29 02:20:32 GMT 2009

Dr. Daniel Carras wrote:
> I'm analyzing the logs now. However, there's not much. All it does is 
> repeatedly ask for NS-record for <root>

You are obviously one the the participants in a DDOS attach in which
your name server is being used as an amplifier. The source IP address
you are seeing is guaranteed to be forged.

This tells me that you have a SERIOUS misconfiguration of your name
servers! You should be refusing these queries!!!

For example, if from some point external to your domain, you query on
your name server, it should behave as follows:

	$ host -t ns . ns1.YOURNAMESERVER
	Using domain server:
	Address: a.b.c.d#53

	Host . not found: 5(REFUSED)

If you have query logging on, you should still see queries, but you
should NEVER return the root hints!!!

PLEASE fix your name servers! It is seriously misconfigured name servers
like yours that is the cause of this problem. If everyone had properly
locked down name servers, DDOS attacks such as this would not work. (And
don't even think of getting me started on network egress filtering!)

For additional details on the type of attack in which you are
participating, see this and other Handler's Diary entries:

See also, recent NANOG archives.

Jon Kibler
