RE: [Full-disclosure] Re: recursive DNS servers DDoS as a growing DDoSproblem



In the scenario you describe, I cannot see any actual amplification...

I'll give you a senario where you can see.

lets say you have 2 name servers that are local to you.

I setup a domain, example.com. In this domain I create a text record which is 100K in length, I don't know, perhaps I paste the source code to decss in it, whatever it's a big text record.

Now I simply spoof a UDP packet using your IP address as the source address and send it to both of your dns servers. This packet is a query for the example.com text record. I have now sent two very small packets and you have received 200K of traffic. That's the amplification, one small udp packet, one large text record in return.

Note, I don't have to use your local servers, but this way it makes it more fun to troubleshoot because it looks like you are the cause of your own flooding..

Geo.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Small Redundant web/mail setup
    ... Subject: Small Redundant web/mail setup ... would serve these files via nfs to the application servers. ... get good hardware. ...
    (freebsd-questions)
  • Re: oops with dual xeon 2.8ghz  4gb ram +smp,qsoftware=A0raid?=,qlvm?=,qand=A0xfs?=
    ... fairly similar setup as yours: ... Running XFS, exporting via NFS ... I have seen quite a lot of Oops's on these servers, ... Regarding ext3... ...
    (Linux-Kernel)
  • Re: Simple setup of domain servers for school labs
    ... routines that perform network setup, user setup, server configuration and ... 2003 SP2 servers setup by a number of contractors. ... all limping along in school labs. ... site support or central support. ...
    (microsoft.public.windows.server.sbs)
  • Re: Antivirus in FC3?
    ... >> a few more people succeed with the setup it will probably be included ... export the home directories to all the servers and do network ... No doubt they are finding that IDEALX scripts need a bunch of work ... manage the LDAP data. ...
    (Fedora)
  • Re: New External DNS
    ... Looking to setup two DNS servers NAT'd to the outside world. ... rather than setting up primary and secondary zones each time. ...
    (microsoft.public.windows.server.dns)