Live data from Hacker News

DDOS on Namecheap Free DNS and Default DNS V2

status.namecheap.com

111–119 of 119 posts

Re: DDOS on Namecheap Free DNS and Default DNS V2

#111
post #45
post #30

Earlier quoted context omitted.

You need to provide some gift to your customers for this downtime. I am using NC for 10 years, every time on bad issues I continue to use. But this outage very bad, I lost money...

If they messed up your cheeseburger, I could see this. How does this help this situation? It doesn't. Namecheap should take that money and invest in their infrastructure.

I'm sure they will. Just a matter of balancing stuff, of course.

Re: DDOS on Namecheap Free DNS and Default DNS V2

#112
post #108
post #106

Earlier quoted context omitted.

Secondary DNS from a normal bind nameserver.

I second this. I'll add that Route 53 would need to respond to notifies for this to be useful.

It's definitely on our list, but in the meantime there is https://code.google.com/p/route53d/ which will let you translate an AXFR/IXFR from a bind server directly into Route 53 authenticated calls.

Re: DDOS on Namecheap Free DNS and Default DNS V2

#113
post #95

Earlier quoted context omitted.

No. The zone file lives on the nameserver (DNS server) which Route 53 provides. Namescheap registers a list of nameservers for your domain with the TLD. An over simplified example for looking up "news.ycombinator.com": 1. First query the TLD nameserver for all ".com" domains asking for the authoritative nameserver(s) for "ycombinator.com". 2. Next query that nameserver for "news.ycombinator.com".

But, the first entry point is namecheap. The domain is at Namecheap, so it will not find the zone file at Route 53, if Namecheap does not send it there. Right?

No, registrar's are your portal to updating data in TLDs, but those TLDs are each operated separately. .com and .net are operated by Verisign, for example.

Re: DDOS on Namecheap Free DNS and Default DNS V2

#114
post #46
post #22

Earlier quoted context omitted.

Just for future reference, it's usually considered a good idea to put your status page on completely independent infrastructure so that it stays up even when the rest of your stuff goes down. A status page that doesn't work during an outage isn't particularly useful.

Good point. The status page is on another cloud but since this is a DNS issue, the subdomain is down. In the future, we'll investigate running this page on a secondary DNS.

Perhaps also investigate allowing customers to slave their own secondary DNS, too? (That is, allow AXFRs.)

This has been a feature requested for, as far as I can tell from the support forums, four years now. It should be possible to make this allowed/disallowed per-zone, and as far as I'm concerned, I don't care who is able to download my tiny zone file. It would allow me to add more diversified DNS servers in the face of things like a DoS against Namecheap.

Re: DDOS on Namecheap Free DNS and Default DNS V2

#115
I recently switched most of my domains to DNSMadeEasy because they are constantly in the top for speed[1], provide a top tier anycast network and for what you get are a great value.

If you want speed and readability I suggest switching to a paid DNS provider.

1: http://www.solvedns.com/dns-comparison/2014/01

BTW I'm not in any way affiliated, just like the service.

Re: DDOS on Namecheap Free DNS and Default DNS V2

#118

Earlier quoted context omitted.

If the hackers really want to take you down, adding another server in isn't very hard...

I suspect the hackers are targeting one of namecheap's customers, not namecheap directly. Because that's usually the case, a good approach is to not give all customers the exact same nameservers.

I agree. We left Network Solutions b/c they were hit 3 times in less than a year. Maybe the website targets moved to Namecheap, so they were targeted also?

Re: DDOS on Namecheap Free DNS and Default DNS V2

#119
post #100

Earlier quoted context omitted.

The only way this would be successful is if the "customer IP's" were spread accross separate networks, and the announcement for the attacked network was sent somewhere else. Assigning customers across lots of IP's in the same /24 isn't going to do anything. A volumetric attack is still going to succeed there. In this landscape of ever-dwindling portable IPv4 subnets, it's harder and harder to get a /24. You won't get…

So namecheap would need a few different, separate IPv4 subnets. Like the ones they already have? http://bgp.he.net/AS22612#_prefixes

Good point. They should be spreading things around more.
Post reply on HN