Out of curiosity, what are the follow ups of an attack like that? The perpetrators are probably using their own servers or compromised clients or servers. Would DNS Simple follow up on this with the abuse/complaint dept of the ISP of the attackers? Are ISP typically responsive to abuse and complaints? If they are not is there any way to black list blocks of IPs assigned to ISP who do not care about being the source o…
I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.
Incident Report – DDoS Attack
21–30 of 40 posts
Re: Incident Report – DDoS Attack
#22Out of curiosity, what are the follow ups of an attack like that? The perpetrators are probably using their own servers or compromised clients or servers. Would DNS Simple follow up on this with the abuse/complaint dept of the ISP of the attackers? Are ISP typically responsive to abuse and complaints? If they are not is there any way to black list blocks of IPs assigned to ISP who do not care about being the source o…
I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.
Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.
Re: Incident Report – DDoS Attack
#23Re: Incident Report – DDoS Attack
#24Earlier quoted context omitted.
I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.
It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list." Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.
Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.
Re: Incident Report – DDoS Attack
#25So who do you think the "well-known third-party service that provides external DDoS protection using reverse DNS proxies" is they're going to use now? CloudFlare?
Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.
Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps.
[1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...
Re: Incident Report – DDoS Attack
#26Earlier quoted context omitted.
It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list." Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.
A lot of ISPs for example in Germany reuse IP addresses and force a reconnect every 24 hours. I don't think showing me banners because the previous "owner" of the IP had a virus is going to improve the situation. Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.
Re: Incident Report – DDoS Attack
#27Earlier quoted context omitted.
Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.
[citation needed] Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps. [1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...
Re: Incident Report – DDoS Attack
#28Earlier quoted context omitted.
[citation needed] Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps. [1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...
Their last significant outage was only 2 months ago: https://blog.cloudflare.com/route-leak-incident-on-october-2...
Re: Incident Report – DDoS Attack
#29Earlier quoted context omitted.
A lot of ISPs for example in Germany reuse IP addresses and force a reconnect every 24 hours. I don't think showing me banners because the previous "owner" of the IP had a virus is going to improve the situation. Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.
Google wouldn't know but the ISP would know who was behind a particular IP at a specific time. They are the ones who should police their network when there are abuses.
No thanks.
Re: Incident Report – DDoS Attack
#30The solution here is one for customers, not providers. Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs). Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results d…
It seems like inbound and outbound zone transfers aren't offered by a number of providers (like AWS). Do you know of a list of DNS providers that support either option?
They have an interesting blog post about setting up secondary DNS: http://blog.easydns.org/2013/09/10/what-we-are-doing-about-c...
I have no affiliation with them, just a happy customer.