Live data from Hacker News

Anonymous plans to take down the 13 root DNS servers that power the Internet?

pastebin.com

31–40 of 108 posts

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#31
post #13
post #9

Most interesting bit : The principle is simple; a flaw that uses forged UDP packets is to be used to trigger a rush of DNS queries all redirected and reflected to those 13 IPs. The flaw is as follow; since the UDP protocol allows it, we can change the source IP of the sender to our target, thus spoofing the source of the DNS query. The DNS server will then respond to that query by sending the answer to the spoofed IP…

Where could we find more information about those 13 servers? Why are there only 13 of them?

http://blog.icann.org/2007/11/there-are-not-13-root-servers/

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#33
post #17

Is it just me or does it seem like this attack will be self-defeating? They are relying on DNS servers to serve responses in order to make DNS servers stop serving responses.

No; the root nameservers have fixed IPs. Those IP addresses, and those of the vulnerable DNS servers to be used as reflectors, can be written down beforehand.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#34

Most of the "root servers" are big anycast clusters. L root has at least 50 locations worldwide...

I think the Anonymous "hackers" are still under the impression that one IP equals one server. Anycast works very well with UDP and they're in for a surprise as their attack is diffused across so many different links.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#37
post #33
post #17

Is it just me or does it seem like this attack will be self-defeating? They are relying on DNS servers to serve responses in order to make DNS servers stop serving responses.

No; the root nameservers have fixed IPs. Those IP addresses, and those of the vulnerable DNS servers to be used as reflectors, can be written down beforehand.

The problem is that, in the DNS spoof attack, the DNS reflectors have to have some data to send "back" to the spoofed IP. If the root servers are down, the reflectors won't have any data to send back, so the flood will stop as the reflectors' caches expire.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#38
post #6

I'm pretty sure every hacker group has gotten this idea at one point or another. Has anyone even come close to taking down all the root DNS servers at once?

Given the built-in resiliency of the DNS system, wouldn't creating an alternative system[1] be more effective in disrupting the status quo?

[1] http://en.wikipedia.org/wiki/AlterNIC

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#39
post #16
post #8

Earlier quoted context omitted.

While the DOS discussed in that link is quite obviously misguided, counterproductive, juvenile and likely criminal, 'terrorism' seems like a pretty strong word.

What is the purpose of the action if not to create some small amount of terror on the part of "our irresponsible leaders"?

DOS is a kind of protest, like a picket line. Protest != terrorism.
Post reply on HN