Live data from Hacker News

DDoS Attack Against Dyn Managed DNS

dynstatus.com

371–380 of 721 posts

Re: DDoS Attack Against Dyn Managed DNS

#371

Relevant (or at least a-propos) post by Bruce Schneier, from a month ago: "Someone Is Learning How to Take Down the Internet" https://www.schneier.com/blog/archives/2016/09/someone_is_le... Edit: And to be clear: I don't mean to imply there's any connection :)

Let's try to put this DDoS attack in some context aside from the technical part.

As @scrollaway mentioned, 6 weeks ago, Bruce Schneier posted that several companies told him that they're detecting attempts to probe their networks and find ways to bring it down https://www.schneier.com/blog/archives/2016/09/someone_is_le...

Now let's look at the progress of events:

- Hillary Clinton's personal email server was hacked a while ago.

- A lone hacker published a document obtained by hacking the DNC servers. The document includes opposition research on Donald Trump and how Hillary can attack him in the election.

- Wikileaks published emails obtained by hacking the DNC

- US intelligence agencies confirmed that Russia was behind the DNC hack

- It was reported that the CIA is starting a cyber attack against Russian targets. http://www.nbcnews.com/news/us-news/cia-prepping-possible-cy...

- This is happening while the war in Syria and Iraq is growing. The Russians are there to "fight ISIS" but they have deployed an air defense system even though ISIS doesn't have any air force.

- Russia's only air craft carrier is trespassing through UK waters to get to Syria in a show of force that doesn't really add anything to their military capabilities there.

https://www.theguardian.com/world/2016/oct/20/russian-fleet-...

https://www.theguardian.com/world/2016/oct/19/convoy-of-russ...

- Finland (yes, Finland) is increasingly worried about Russia. They violated their air space, and they're questioning Finland's independence. Finland shares a long boarder with Russia.

http://www.businessinsider.com/r-finland-sees-propaganda-att...

- US ships were attacked near Yemen after they're bombed some targets the belong to the rebels. https://www.theguardian.com/us-news/2016/oct/13/us-enters-ye...

- US election is in 3 weeks and Donald Trump is openly in love with Putin. Trump questioned the benefit of NATO which is the basis for Europe stability after the 2nd world war.

Say Hello to World War III, everybody!

Re: DDoS Attack Against Dyn Managed DNS

#373
post #363
post #327

To get on github you can add to your /etc/hosts: 192.30.253.113 github.com 151.101.32.133 assets-cdn.github.com And it seems faster than normal right (less users). Edit; for profile pics include: 151.101.32.133 avatars0.githubusercontent.com 151.101.32.133 avatars1.githubusercontent.com 151.101.32.133 avatars2.githubusercontent.com 151.101.32.133 avatars3.githubusercontent.com 151.101.32.133 avatars4.githubuserconten…

how about npm?

you can get the ip from a different location using this: https://www.whatsmydns.net/

Re: DDoS Attack Against Dyn Managed DNS

#374
post #255

Earlier quoted context omitted.

OpenDNS does this: https://support.opendns.com/hc/en-us/articles/227987767-Dyna... It's called SmartCache.

Anyone know if Google Public DNS does?

It doesn't (first result is openDNS, second is google):

    $ dig -tA twitter.com @208.67.222.222

    ; > DiG 9.8.3-P1 > -tA twitter.com @208.67.222.222
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER> DiG 9.8.3-P1 > -tA twitter.com @8.8.8.8
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER

Re: DDoS Attack Against Dyn Managed DNS

#375
post #311

Earlier quoted context omitted.

What can they do? It's not Twitter themselves being DDOS'd, it's a DNS provider. This propagates up the chain to impact both a Tier 1 network and cloud providers, which hits tons of stuff on top of that.

Have a failover DNS provider. Amazon uses Dyn, but also has UltraDNS as a backup, and it's obviously still up. Twitter vs Amazon: host -t ns twitter.com: ns3.p34.dynect.net, ns4.p34.dynect.net, ns1.p34.dynect.net, ns2.p34.dynect.net. host -t ns amazon.com: ns3.p31.dynect.net, ns4.p31.dynect.net, ns2.p31.dynect.net, pdns6.ultradns.co.uk, pdns1.ultradns.net, ns1.p31.dynect.net.

Thank you so much for mentioning this. This was my first thought when I heard about all the major enterprise sites affected by the DDoS:

"How do all these major players have singly-homed DNS"?

Re: DDoS Attack Against Dyn Managed DNS

#377
post #327

To get on github you can add to your /etc/hosts: 192.30.253.113 github.com 151.101.32.133 assets-cdn.github.com And it seems faster than normal right (less users). Edit; for profile pics include: 151.101.32.133 avatars0.githubusercontent.com 151.101.32.133 avatars1.githubusercontent.com 151.101.32.133 avatars2.githubusercontent.com 151.101.32.133 avatars3.githubusercontent.com 151.101.32.133 avatars4.githubuserconten…

How about *.github.io?

Edit: saw your other reply and looked it up myself, it's 23.235.33.133

Re: DDoS Attack Against Dyn Managed DNS

#378

Earlier quoted context omitted.

thanks for the tip! how did you determine the ELB address behind the ssl endpoint? edit: figured it out. What i did was do: nslookup your-SSL-endpoint.herokussl.com then you'll see the elb address. Switch to the openDNS servers helpfully pointed out by someone above first...

Presumably with something like `dig @208.67.220.220 -t CNAME .herokussl.com`. This uses the OpenDNS nameservers, that people have been reporting as working. Haven't tested it as I am on the go.

thanks! figured it out but appreciate the help!!

Re: DDoS Attack Against Dyn Managed DNS

#379

Relevant (or at least a-propos) post by Bruce Schneier, from a month ago: "Someone Is Learning How to Take Down the Internet" https://www.schneier.com/blog/archives/2016/09/someone_is_le... Edit: And to be clear: I don't mean to imply there's any connection :)

> The Department of Homeland Security told CNBC that it is "looking into all potential causes" of the attack. http://www.cnbc.com/2016/10/21/major-websites-across-east-co... Is this par for course for all large DDOS attacks or did something tip them off?

More like for the first time in a long time, serious negative economic impact is occurring. I sincerely wish this was a wake up call, but it won't be.

Re: DDoS Attack Against Dyn Managed DNS

#380
post #317

Earlier quoted context omitted.

The rogue ISPs thought they were helping people by serving stale data. After all, better something past its use-by date than failing, right? A low tolerance for DNS response times, and suddenly large chunks of the internet are failing a lot... Among other problems, this enables attacks. Leak a route, DDoS a DNS provider, and watch as traffic everywhere goes to an attack server because servers everywhere "protect" peo…

You seem to be continuing to warn against a proposal that isn't the one that was made. What specifically is dangerous about using cached records only in the case of the upstream servers failing to reply?

It doesn't take much of an imagination to attack this.

The older I get in tech the more I realize we just go in circles re-implementing every bad idea over again for the same exact reasons each "generation". Ah well.

TTL is TTL for a reason. It's simple. The publisher is in control, they set their TTL for 60 seconds so obviously they have robust DNS infrastructure they are confident in. They are also signaling with such low TTLs that they require them technically in order to do things like load balance or HA or need them for a DR plan.

Now I get a timeout. Or a negative response. What is the appropriate thing to do? Serve the last record I had? Are you sure? Maybe by doing so I'm actually redirecting traffic they are trying to drain and have now increased traffic at a specific point that is actually contributing to the problem vs. helping. How many queries do I get to serve out of my "best guess" cache before I ask again? How many minutes? Obviously a busy resolver (millions of qps at many ISPs) can't be checking every request so where do you draw the line?

It's just arrogant I suppose. The publisher of that DNS record could set a 30 day TTL if they wanted to, and completely avoid this. But they didn't, and they usually have a reason for that which should be respected. We have standards for a reason.

Post reply on HN