> A new customer signed up for our service and brought in multiple domains that were already facing a DDoS attack. The customer had already tried at least 2 other providers before DNSimple. Once the domains were delegated to us, we began receiving the traffic from the DDoS. I'm curious did they know this in advance or discovered it after the fact? I often wonder about business models where the core expense is "unlimi…
Anthony from DNSimple here. We discovered it after the fact, via a tip from other DNS providers.
Incident Report – DDoS Attack
31–40 of 40 posts
Re: Incident Report – DDoS Attack
#32I need to learn to let things go, but: https://news.ycombinator.com/item?id=4280515 I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling c…
I swear by Route53, it is the only service I use on AWS and I have moved a lot of my clients over to it.
Re: Incident Report – DDoS Attack
#33> A new customer signed up for our service and brought in multiple domains that were already facing a DDoS attack. The customer had already tried at least 2 other providers before DNSimple. Once the domains were delegated to us, we began receiving the traffic from the DDoS. I'm curious did they know this in advance or discovered it after the fact? I often wonder about business models where the core expense is "unlimi…
to pull it off properly as a service provider, you really need to have a solid understanding of user usage patterns.
one of the big problems that tips the low/high utilization ratio unfavorably is that unlimited plans that are primarily marketed for being unlimited tend to attract users in the high utilization bracket.
so the challenge for service providers is not just understanding users and understanding that ratio but figuring out how you are going to market to, and signup, those users who will be in the low utilization bracket and will essentially be paying for something they won't be user (which is hard to do)
it isn't hard to find case studies of companies that launch optimistically with one pricing plan around unlimited, to then only go back and revise their pricing and break promises because they didn't understand their users and were unable to market to and signup low utilization users.
one recent example is Bitcasa
Re: Incident Report – DDoS Attack
#34Earlier quoted context omitted.
I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.
It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list." Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.
This particular DDoS I actually believe is _not_ due to a botnet, or at least believe there is insufficient evidence either way. The attack appears to be using a technique/infrastructure I’ve been passively tracking for nearly a year, wherein the attack DNS requests are spoofed to appear from seemingly-random clients and sent to open recursive DNS servers across the Internet. This makes the attack look like a botnet to superficial analysis on the target side, but this isn’t necessarily the case. In the small amount of time I’ve so-far invested in trying to track down the origin, I have yet to observe generation of the initial query packets.
Re: Incident Report – DDoS Attack
#35Earlier quoted context omitted.
I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.
Remember to keep any machine under your control up to date! I'm looking at you, XP die-hards. If you're able to, monitor your network traffic periodically as well.
Re: Incident Report – DDoS Attack
#36I need to learn to let things go, but: https://news.ycombinator.com/item?id=4280515 I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling c…
I really don't understand why some of these low-grade DNS hosting services are so popular when Route53 is available. With Route53 you get a top-grade DNS service that is equivalent, if not better, than the enterprise hosted DNS solutions but at the price of the low-end consumer style services. I swear by Route53, it is the only service I use on AWS and I have moved a lot of my clients over to it.
Re: Incident Report – DDoS Attack
#37Earlier quoted context omitted.
Remember to keep any machine under your control up to date! I'm looking at you, XP die-hards. If you're able to, monitor your network traffic periodically as well.
It's easy to toss out statements like "monitor your network traffic"; do you have any good suggestions for how an average developer with relatively little understanding of networking can go about doing so?
Re: Incident Report – DDoS Attack
#38Earlier quoted context omitted.
I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.
It'd be nice if IPs involved in botnet DDoS's could go into a public registry, then get a banner from Google saying, "Hey, you might have a virus, someone reported you to this list." Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.
Unfortunately this is already in use with some malicious ads as well as phone scams to get people to give remote access to overseas tech centers that then scam them into paying good money for nothing.
To date the only tech line about this is, "nobody legitimate will ever contact you to tell you you're infected with a virus."
So I don't know how you could develop trust in that environment.
Re: Incident Report – DDoS Attack
#39Earlier quoted context omitted.
Remember to keep any machine under your control up to date! I'm looking at you, XP die-hards. If you're able to, monitor your network traffic periodically as well.
It's easy to toss out statements like "monitor your network traffic"; do you have any good suggestions for how an average developer with relatively little understanding of networking can go about doing so?
Re: Incident Report – DDoS Attack
#40Earlier quoted context omitted.
Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.
[citation needed] Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps. [1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...
Granted we are probably more vulnerable to DoS, but our general uptime is far better now.