Live data from Hacker News

Incident Report – DDoS Attack

blog.dnsimple.com

21–30 of 40 posts

Re: Incident Report – DDoS Attack

#21
post #17

Out of curiosity, what are the follow ups of an attack like that? The perpetrators are probably using their own servers or compromised clients or servers. Would DNS Simple follow up on this with the abuse/complaint dept of the ISP of the attackers? Are ISP typically responsive to abuse and complaints? If they are not is there any way to black list blocks of IPs assigned to ISP who do not care about being the source o…

I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.

Remember to keep any machine under your control up to date! I'm looking at you, XP die-hards. If you're able to, monitor your network traffic periodically as well.

Re: Incident Report – DDoS Attack

#22
post #17

Out of curiosity, what are the follow ups of an attack like that? The perpetrators are probably using their own servers or compromised clients or servers. Would DNS Simple follow up on this with the abuse/complaint dept of the ISP of the attackers? Are ISP typically responsive to abuse and complaints? If they are not is there any way to black list blocks of IPs assigned to ISP who do not care about being the source o…

I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.

It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list."

Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.

Re: Incident Report – DDoS Attack

#24

Earlier quoted context omitted.

I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.

It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list." Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.

A lot of ISPs for example in Germany reuse IP addresses and force a reconnect every 24 hours. I don't think showing me banners because the previous "owner" of the IP had a virus is going to improve the situation.

Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.

Re: Incident Report – DDoS Attack

#25
post #6
post #3

So who do you think the "well-known third-party service that provides external DDoS protection using reverse DNS proxies" is they're going to use now? CloudFlare?

Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.

[citation needed]

Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps.

[1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...

Re: Incident Report – DDoS Attack

#26

Earlier quoted context omitted.

It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list." Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.

A lot of ISPs for example in Germany reuse IP addresses and force a reconnect every 24 hours. I don't think showing me banners because the previous "owner" of the IP had a virus is going to improve the situation. Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.

Google wouldn't know but the ISP would know who was behind a particular IP at a specific time. They are the ones who should police their network when there are abuses.

Re: Incident Report – DDoS Attack

#27
post #6

Earlier quoted context omitted.

Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.

[citation needed] Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps. [1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...

Their last significant outage was only 2 months ago: https://blog.cloudflare.com/route-leak-incident-on-october-2...

Re: Incident Report – DDoS Attack

#28
post #27

Earlier quoted context omitted.

[citation needed] Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps. [1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...

Their last significant outage was only 2 months ago: https://blog.cloudflare.com/route-leak-incident-on-october-2...

As the blog post outlines, the outage was related to an upstream network provider leaking routes. Note exactly something we can prevent for them.

Re: Incident Report – DDoS Attack

#29
post #26

Earlier quoted context omitted.

A lot of ISPs for example in Germany reuse IP addresses and force a reconnect every 24 hours. I don't think showing me banners because the previous "owner" of the IP had a virus is going to improve the situation. Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.

Google wouldn't know but the ISP would know who was behind a particular IP at a specific time. They are the ones who should police their network when there are abuses.

The original proposal was that google delivers the ads. So google would have to contact my ISP who would then have to return whether or not I was using any of the given "spammy" IPs at the time that they were spammy - or my ISP would have to deliver the banner.

No thanks.

Re: Incident Report – DDoS Attack

#30
post #12
post #5

The solution here is one for customers, not providers. Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs). Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results d…

It seems like inbound and outbound zone transfers aren't offered by a number of providers (like AWS). Do you know of a list of DNS providers that support either option?

EasyDNS provides integration with AWS: http://easyroute53.com/

They have an interesting blog post about setting up secondary DNS: http://blog.easydns.org/2013/09/10/what-we-are-doing-about-c...

I have no affiliation with them, just a happy customer.

Post reply on HN