Live data from Hacker News

Attack on DNS root servers

root-servers.org

91–97 of 97 posts

Re: Attack on DNS root servers

#91
post #84

Earlier quoted context omitted.

Nobody would tamper with this content.

China injected javascript malware into non-https traffic that joined the users into a botnet that launched a DDOS attack on Github. The "Great Cannon".

The "Great Cannon" only targeted foreign traffic destined for Chinese websites. This one is not.

Re: Attack on DNS root servers

#92
post #80

Earlier quoted context omitted.

Nobody would tamper with this content.

That's not actually true. There have been several documented examples now of people injecting stuff into HTTP requests when they pass by (ISPs injecting notifications, ads, people running proxies injecting malicious javascript, etc).

It's completely true. This content would never be targeted for MITM.

It's a dashboard for displaying the global locations of DNS root servers and links to their authoritative organizations. Not only is this an incredibly niche site, all DNS root server information is replicated around the world by multiple organizations. Nobody uses this site to maintain their DNS trusts, it probably gets incredibly low traffic, and going out of your way to MITM it would be a lot of work for no payoff. This is a terrible target. Nobody would bother.

Re: Attack on DNS root servers

#93
post #84

Earlier quoted context omitted.

China injected javascript malware into non-https traffic that joined the users into a botnet that launched a DDOS attack on Github. The "Great Cannon".

The "Great Cannon" only targeted foreign traffic destined for Chinese websites. This one is not.

Yes but they just as easily could have targeted traffic to this site as well.

Also a number of ISPs and wifi hotspots inject ads, and I know Verizon injected a tracking header based on your mobile plan.

Re: Attack on DNS root servers

#94
post #93

Earlier quoted context omitted.

The "Great Cannon" only targeted foreign traffic destined for Chinese websites. This one is not.

Yes but they just as easily could have targeted traffic to this site as well. Also a number of ISPs and wifi hotspots inject ads, and I know Verizon injected a tracking header based on your mobile plan.

So Verizon is going to inject some 0day malware into this page to, what, serve you more ads?

If you're concerned about tracking cookies or headers, get a plug-in to stop it. Every website on the planet should not need to use https just because Verizon wants to make money off targeted ads.

And nobody is attacking this page to hack individuals. Of course you can. Security isn't about preventing every single possible attack from every possible angle. It's about making attacks more difficult when one is plausible or likely. Nobody will attack you through this particular website. So https is not needed to prevent a targeted attack.

Re: Attack on DNS root servers

#95
post #65
post #26

Earlier quoted context omitted.

Is it really that trivial to fake source IP? I think pretty much any ISP wouldn't let such packets through (or am I missing something?), and you are also easier to find then (well, if you are not careful that is).

Reality check: ~30% of active AS worldwide don't drop spoofed packets originating from their networks. http://spoofer.cmand.org/summary.php

It is a bit like polluting the ocean by dumping wastes. It cost less for the polluters if they are not caught.

For "typical AS router", is it easy or cheap to block spoofed packets?

I wonder if that test software/website can/should "OUT / Shame" the AS routing subnets as "Major Internet Polluters" and publish a monthly reports to shame that 30% polluters.

Re: Attack on DNS root servers

#96

Earlier quoted context omitted.

20 Gbps definitely isn't very impressive given the current landscape, but it can probably take down many medium-sized businesses as well, if they have no DDoS mitigations. Even a large one, if they somehow had no mitigations or no decent security team.

20Gbps is actually still impressive if it is a set of valid requests like the parent seems to imply when doing the calculations. 20Gbps via a reflection technique is easy, but also relatively easy to filter and just requires a large pipe. 20Gbps of traffic doing legitimate requests that you can't immediately and trivially filter/rule out is still an impressive feat right now.

It's high, but DDoSs over 500 Gbps have been observed in the past 2 years. So relatively speaking, it's not that extraordinary.

Re: Attack on DNS root servers

#97
post #80

Earlier quoted context omitted.

That's not actually true. There have been several documented examples now of people injecting stuff into HTTP requests when they pass by (ISPs injecting notifications, ads, people running proxies injecting malicious javascript, etc).

It's completely true. This content would never be targeted for MITM. It's a dashboard for displaying the global locations of DNS root servers and links to their authoritative organizations. Not only is this an incredibly niche site, all DNS root server information is replicated around the world by multiple organizations. Nobody uses this site to maintain their DNS trusts, it probably gets incredibly low traffic, and…

It's not strictly about targeted attacks. There are people who modify unencrypted content that passes through their system regardless of what content it is. There have been several presentations on this topic, but I'll link the slides for one [0]. Here's an article about an ISP injecting ads in case you don't think this sort of thing happens in real systems [1].

[0] https://www.defcon.org/images/defcon-17/dc-17-presentations/...

[1] http://arstechnica.com/tech-policy/2013/04/how-a-banner-ad-f...

Post reply on HN