Re: recursive DNS servers DDoS as a growing DDoS problem



Geo. wrote:
What is stopping you from running your own local DNS server?

What is stopping you from running your own SMTP server? A port 25 block?
Well if an ISP doesn't want to play whack-a-mole with unsecured dns servers
popping up every day do you not think it likely that they will resort to the
same techniques they used for smtp?

Granted a port 53 inbound block would make more sense for the current
example but just like bots started running their own SMTP engines I see the
dns flood model changing to fit the new landscape.

We have done just this (block inbound udp/53) to certain subnets due to a
rash of CPEs that happily proxy DNS, including recursive queries, from their
WAN side. They DoS their own circuits more effectively than the intended DoS
targets.

Ingress/Egress filtering did not help because the traffic coming to the name
server was not spoofed to appear like it was coming from our network, it
really was. The attack reflected off of the routers and because they were
local to our name servers, they got replies to the recursive queries despite
our rejecting them from outside our network. And of course once it was
cached, it was open for public queries.

Broken/misconfigured/buggy routers appear to look just like open DNS
servers, and are likely to be much higher in numbers.

Jim



Relevant Pages

  • Re: Problem sending email out of Exchange 2003
    ... My problem was resolved last night when it was found that Exchange was not ... referring DNS queries to SBS but instead had been given specific DNS ... Exchange SMTP was no longer able to query these servers. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange 2000 problem - absolutely desperate, please help...
    ... an error regarding an internal DNS error, I'd check your DNS settings first. ... servers as forwarders and entered the new ISP's DNS servers as forwarders. ... > Exchange system manager I found the SMTP connector. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Problem sending email out of Exchange 2003
    ... instances but would like to get away from the SMTP connector. ... SPF record my solidify those domains Exchagne servers behind the ATT DSL/T1 ... Set the router as DNS forwarder. ... SMTP connector to smtp-server.wi.rr.com, then email goes out as it ...
    (microsoft.public.windows.server.sbs)
  • Re: advise on smtp service (windows 2003 SP2)
    ... What I'm wondering about is plenty of email servers (in ... VERY strict about RFC rules. ... I'm trying to get smtp service on 2003 server to let me relay from ... port 25 to gmail. ...
    (microsoft.public.windows.server.general)
  • Re: RE: application for an employment
    ... Using a web server is NOT a port scan - in any manner. ... To alleviate some ignorance regarding the DNS process and public servers. ... This is NOT if anyone can connect to port 53 and use them. ...
    (Security-Basics)