Live data from Hacker News

Anonymous plans to take down the 13 root DNS servers that power the Internet?

pastebin.com

51–60 of 108 posts

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#51
post #8

Earlier quoted context omitted.

While the DOS discussed in that link is quite obviously misguided, counterproductive, juvenile and likely criminal, 'terrorism' seems like a pretty strong word.

It's not just this. Every single time a new link is posted about Anonymous it's some form of digital terrorism. It has barely a purpose and only serves to disrupt the masses. They even have made threats that they would do X if Y isn't done. This is terrorism to me.

This is a serious question:

Are you actually in a state of terror by this Pastebin entry, or are you just saying it's rhetorical 'terrorism'?

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#52
post #37
post #33

Earlier quoted context omitted.

No; the root nameservers have fixed IPs. Those IP addresses, and those of the vulnerable DNS servers to be used as reflectors, can be written down beforehand.

The problem is that, in the DNS spoof attack, the DNS reflectors have to have some data to send "back" to the spoofed IP. If the root servers are down, the reflectors won't have any data to send back, so the flood will stop as the reflectors' caches expire.

So it's not just me. Thanks.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#53

Earlier quoted context omitted.

Here.[1] Most of them are not single-box servers, but cluster with multisite redundancy. That's why all attacks were unsuccessful in the past. 1. http://en.wikipedia.org/wiki/Root_name_server

So could organizations build their own Root NS cluster and be added to the 13 that already exist? Do I misunderstand something as to why there are only 13, who controls them, etc?

And so Google Public DNS is not really related to these Root NS then. They just simply offer it as a service for those that want to use it.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#54
I think Anonymous doesn't really know how DNS works. The root nameservers don't serve zone data for most sites that people use anyways.

DNS is a distributed hierarchy for serving requests. It's designed to be fault-tolerant because if every name resolution (google.com->8.8.8.8) performed by a browser had to reach 13 servers in the world, we'd still be using gopher and newsgroups instead of the web.

DNS is distributed, hierarchical, redundant, and cached all over the place as much as possible. Even my laptop caches DNS queries until a reboot. Even if a DNS cache misses (which is infrequent), it goes to the nameserver hosting the zone, which isn't a root name server.

Bottom line, it's probably just a joke designed to get some attention and to experiment and see what actually does happen if you hit those servers.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#55
post #37
post #33

Earlier quoted context omitted.

No; the root nameservers have fixed IPs. Those IP addresses, and those of the vulnerable DNS servers to be used as reflectors, can be written down beforehand.

The problem is that, in the DNS spoof attack, the DNS reflectors have to have some data to send "back" to the spoofed IP. If the root servers are down, the reflectors won't have any data to send back, so the flood will stop as the reflectors' caches expire.

Possibly. I haven't read the particular technique they're planning to use here, but I recall some old attacks against Bind relied on query reflection, which might work in the absence of cached data.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#56

Earlier quoted context omitted.

The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)

Most ISP's dns cache servers honor the TTL defined in the authoritative SOA records, unless is 1 minute or less. I think the average TTL time for a dns zone would be measured in minutes. It needs to be that low in order to do SRV load-balancing, A/B testing, etc. In any case, in the highly unlikely event that they manage to overload the 13 servers, there's plenty of time for every domain to temporarily extend the TTL…

Most TTLs for nameservers are on the order of days.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#57
post #44
post #15

Earlier quoted context omitted.

ok, thanks for the clarification. what confused me was "thus, disabling the HTTP Internet" i'm kinda glad they're attempting this, IMO. i'm tired of ignorant people not understanding what the "web" really is, and how important it is to keep it free and open. sure, this might make "hackers" look bad, but honestly, if we sit back and do nothing, then we cannot complain when laws are passed, etc.. if they pull this off,…

Did you seriously just ask how the web works, then complain about ignorant people who don't know how the web works...? What does hackers using DDoS to knock a service offline have to do with it being free/open? Everything isn't about SOPA/ACTA/et al...

no. are you really trying to start an argument? clearly, you knew what i meant.

there is a difference between a web developer who did not understand some specifics regarding a protocol and a "average joe" user who does not even know what a protocol is.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#58
post #13
post #9

Most interesting bit : The principle is simple; a flaw that uses forged UDP packets is to be used to trigger a rush of DNS queries all redirected and reflected to those 13 IPs. The flaw is as follow; since the UDP protocol allows it, we can change the source IP of the sender to our target, thus spoofing the source of the DNS query. The DNS server will then respond to that query by sending the answer to the spoofed IP…

Where could we find more information about those 13 servers? Why are there only 13 of them?

Not only are there more than 13 of them, most of the root servers are now being served by anycast, so the same IP address corresponds to many servers around the globe.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#60
post #8

Earlier quoted context omitted.

While the DOS discussed in that link is quite obviously misguided, counterproductive, juvenile and likely criminal, 'terrorism' seems like a pretty strong word.

It's not just this. Every single time a new link is posted about Anonymous it's some form of digital terrorism. It has barely a purpose and only serves to disrupt the masses. They even have made threats that they would do X if Y isn't done. This is terrorism to me.

Do you classify strike action by unions as terrorism? Unions threaten to do X if Y isn't done and end up disrupting the masses.
Post reply on HN