Live data from Hacker News

Anonymous plans to take down the 13 root DNS servers that power the Internet?

pastebin.com

101–108 of 108 posts

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#101
post #65

Earlier quoted context omitted.

Please prove this assertion by posting the address of a resolver that behaves as you describe.

There are more polite and productive ways of asking for proof of the phenomenon. Or, better yet, use Google the way it was meant to be used, and find out for yourself (just search for stories about DNS migration/propagation issues). People have documented visits to their old IP addresses for a very long time (much longer than the TTL) after updating their DNS with new IP addresses.

I don't see how you could construe my comment as being in anyway impolite.

Google does not turn up any useful results for this subject. The only reference I've seen to resolvers doing something unusual with caching is on the dns-operations mailing list where I ran into a fellow who doesn't cache records with a TTL less than a minute.

Since you claim it is simple to find a resolver that extends the TTL beyond what the authoritative server has specified, can you please point me to such a resolver?

EDIT: Just to be clear, I'm after a server that I can query or something equally authoritative.

EDIT2: My apologies if this is seen as belaboring but please note that nicksuan's comment is not referring to CPE, stub resolvers or client apps.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#102
post #101

Earlier quoted context omitted.

There are more polite and productive ways of asking for proof of the phenomenon. Or, better yet, use Google the way it was meant to be used, and find out for yourself (just search for stories about DNS migration/propagation issues). People have documented visits to their old IP addresses for a very long time (much longer than the TTL) after updating their DNS with new IP addresses.

I don't see how you could construe my comment as being in anyway impolite. Google does not turn up any useful results for this subject. The only reference I've seen to resolvers doing something unusual with caching is on the dns-operations mailing list where I ran into a fellow who doesn't cache records with a TTL less than a minute. Since you claim it is simple to find a resolver that extends the TTL beyond what the…

Your original comment is impolite because it is presented as a demand without any explanation. A demand of proof without explanation can be interpreted as an accusation of lying. Something like, "I haven't seen this phenomenon myself; could you link to some example bad ISPs or articles documenting it?" would be much better.

As for proof, I'm not a professional sysadmin, but based on my reading the most proof you're likely to get is indirect proof in the form of requests to IP addresses long after they've been removed from DNS. If those requests are concentrated in a few ISP subnets, it's reasonable to infer that it's the ISP, not customer equipment, that is caching beyond TTL.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#103
post #101

Earlier quoted context omitted.

I don't see how you could construe my comment as being in anyway impolite. Google does not turn up any useful results for this subject. The only reference I've seen to resolvers doing something unusual with caching is on the dns-operations mailing list where I ran into a fellow who doesn't cache records with a TTL less than a minute. Since you claim it is simple to find a resolver that extends the TTL beyond what the…

Your original comment is impolite because it is presented as a demand without any explanation. A demand of proof without explanation can be interpreted as an accusation of lying. Something like, "I haven't seen this phenomenon myself; could you link to some example bad ISPs or articles documenting it?" would be much better. As for proof, I'm not a professional sysadmin, but based on my reading the most proof you're l…

Your interpretation of my original comment seems extremely hypersensitive to me. Perhaps there is cultural difference at play here.

The experience I've had in hosting ten-thousand odd zones suggests that these resolvers do not exist. I've seen a great many claims but am yet to actually see a resolver that extends TTLs in the wild and so I consider them all but myth.

In the past there has been issues at the client - predominately with browsers, MTAs and stub-resolvers - so if I were to observe activity that suggested a stale cache I'd be more likely to attribute it to a bug (be it new or old) if no other data were available.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#106

Earlier quoted context omitted.

TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much). TOR itself filters it: Also, remember that many of their more subtle communication mechanisms (like spoofed UDP packets) can't be used over Tor, because it only transports correctly-formed TCP connections. My guess is that they're just clueless.

I suspect they were planning to use Tor for command and control. Odd that it was only a requirement for the Windows software though. Perhaps they script its installation on the Linux side.

Command and control, of what? The ramp instances? Why would they need that?

And if the actual attack is direct, how will they escape the ISP's filters? According to The Spoofer Project[1], no ISP lets you spoof packets with IPs outside of at least the same /8 subnet. Can you even get a consumer connection with an IP in those subnets?

[1]: http://spoofer.csail.mit.edu/summary.php

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#107
post #90
post #81

Earlier quoted context omitted.

if you're in the ambulance, or think you might be, and are refused access to life-saving medicine, you will be terrified. Terrorism is using force or the threat of force against a population to achieve political or economic goals. That is chapter and verse what Anon is doing with these threats. There are (obviously) degrees of terrorism. Hitting buildings with planes isn't the same as sending a few letters with anthr…

> Terrorism is using force or the threat of force > against a population to achieve political or economic > goals A bunch of people handcuffed in a circle around a hospital doesn't have anything to do with 'force.' Just sayin'.

Inertia == force. Just sayin'

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#108

Earlier quoted context omitted.

I suspect they were planning to use Tor for command and control. Odd that it was only a requirement for the Windows software though. Perhaps they script its installation on the Linux side.

Command and control, of what? The ramp instances? Why would they need that? And if the actual attack is direct, how will they escape the ISP's filters? According to The Spoofer Project[1], no ISP lets you spoof packets with IPs outside of at least the same /8 subnet. Can you even get a consumer connection with an IP in those subnets? [1]: http://spoofer.csail.mit.edu/summary.php

> Command and control, of what? The ramp instances?

That's what I was thinking. But I'm just guessing without having downloaded the package.

> Why would they need that?

It's hard to know the motivations behind the person who wrote the Pastebin, but if you were to go to all the trouble to amass an army of bots with the capability of sending arbitrary packets with forged source IPs, wouldn't you want to retain some degree of control over it?

> And if the actual attack is direct, how will they escape the ISP's filters? According to The Spoofer Project[1], no ISP lets you spoof packets with IPs outside of at least the same /8 subnet. Can you even get a consumer connection with an IP in those subnets?

(Thank you for that fascinating link BTW.)

I dunno, the same thought occurred to me too.

Note that they encourage the use of "VPNs", though they don't specify to where. Maybe "VPN" to their audience is expected to represent some sort of anonymizing service (e.g. for illicit filesharing) that typically terminates at a backend datacenter which might not have effective egress filtering.

Again, just speculating.

Post reply on HN