<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Verdana;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
mso-ligatures:standardcontextual;
mso-fareast-language:EN-US;}
span.E-mailStijl17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=NL link="#0563C1" vlink="#954F72" style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal>Hello,<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><span lang=EN-US>I have 2 dns servers.<br>Both running on centos with his own replicated mysql backends<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>Yesterday both dns servers stopped responding for 3 minutes.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>In the periode of 3 minutes I see a lot of lines for the same domain.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Pdns that was restared by it self and again the fluid of this domain…<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 91.202.230.18 wants 'lp2.xxx.com|A', do = 1, bufsize = 1232 (4096): packetcache MISS<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 46.51.160.145 wants 'ns34.xxx.com|A', do = 1, bufsize = 1232: packetcache MISS<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 192.73.240.129 wants 'thai.xxx.com|A', do = 1, bufsize = 1232: packetcache MISS<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 146.112.128.69 wants 'auth-hack.xxx.com|A', do = 1, bufsize = 1232 (1410): packetcache HIT<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 117.54.16.252 wants 'payments.xxx.com|A', do = 1, bufsize = 1232 (4096): packetcache MISS<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 2a02:2f0e:5fff:ffff::2 wants 'skyline.xxx.com|A', do = 1, bufsize = 1232 (4096): packetcache MISS<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:40:47 ns1 pdns_server[2135429]: Remote 2a04:c602:409:fe::27 wants 'app3.xxx.com|A', do = 1, bufsize = 1232: packetcache MISS<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>After this:<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: pdns.service: Service RestartSec=1s expired, scheduling restart.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: pdns.service: Scheduled restart job, restart counter is at 59.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: Stopped PowerDNS Authoritative Server.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: Starting PowerDNS Authoritative Server...<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 rsyslogd[795583]: imjournal: 102527 messages lost due to rate-limiting (20000 allowed within 600 seconds)<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: Started PowerDNS Authoritative Server.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: pdns.service: Main process exited, code=exited, status=1/FAILURE<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:36 ns1 systemd[1]: pdns.service: Failed with result 'exit-code'.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:37 ns1 systemd[1]: pdns.service: Service RestartSec=1s expired, scheduling restart.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:37 ns1 systemd[1]: pdns.service: Scheduled restart job, restart counter is at 60.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:37 ns1 systemd[1]: Stopped PowerDNS Authoritative Server.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>-----<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:51 ns1 systemd[1]: Starting PowerDNS Authoritative Server...<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 systemd-journald[218]: Suppressed 80113 messages from pdns.service<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: Failed to retrieve security status update for '4.8.2' on 'auth-4.8.2.security-status.secpoll.powerdns.com.': RCODE was Server Failure<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: gmysql Connection successful. Connected to database 'powerdns' on '127.0.0.1'.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: Creating backend connection for TCP<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: Primary/secondary communicator launching<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: gmysql Connection successful. Connected to database 'powerdns' on '127.0.0.1'.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: gmysql Connection successful. Connected to database 'powerdns' on '127.0.0.1'.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US>Oct 18 21:42:53 ns1 pdns_server[2514841]: About to create 3 backend threads for UDP<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US>Than again a lot of the same lines for the same domain.<br>afther 3:36 minutes dns was responding normaly and the request are back to normal.<br>So It looks like some kind of attack.<br><br>Is there something that I can do to prevent this from the future.<br><br><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p><table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0 width=302 style='margin-left:-1.5pt'><tr style='height:66.9pt'><td width=194 valign=top style='width:145.55pt;padding:0cm 0cm 9.0pt 7.5pt;height:66.9pt'><p class=MsoNormal style='line-height:12.75pt'><span style='font-size:10.0pt;font-family:"Verdana",sans-serif;color:#464646;mso-ligatures:none;mso-fareast-language:NL'>Met vriendelijke groet,</span><span style='font-family:"Verdana",sans-serif;color:#464646;mso-ligatures:none;mso-fareast-language:NL'><o:p></o:p></span></p><p class=MsoNormal style='line-height:12.75pt'><span style='font-size:10.0pt;font-family:"Verdana",sans-serif;color:#464646;mso-ligatures:none;mso-fareast-language:NL'><o:p> </o:p></span></p><p class=MsoNormal style='line-height:12.75pt'><span style='font-size:10.0pt;font-family:"Verdana",sans-serif;color:#464646;mso-ligatures:none;mso-fareast-language:NL'>Steffan Noord<o:p></o:p></span></p><p class=MsoNormal style='line-height:12.75pt'><span style='font-size:10.0pt;font-family:"Verdana",sans-serif;color:#464646;mso-ligatures:none;mso-fareast-language:NL'><o:p> </o:p></span></p><p class=MsoNormal style='line-height:12.75pt'><span style='font-size:8.0pt;font-family:"Arial",sans-serif;mso-ligatures:none;mso-fareast-language:NL'><o:p> </o:p></span></p></td><td width=108 valign=top style='width:80.7pt;padding:0cm 7.5pt 0cm 0cm;height:66.9pt'></td></tr><tr style='height:44.9pt'><td width=302 colspan=2 valign=top style='width:226.25pt;padding:0cm 0cm 0cm 0cm;height:44.9pt'></td></tr></table><p class=MsoNormal><span style='mso-ligatures:none;mso-fareast-language:NL'><o:p> </o:p></span></p><p class=MsoNormal><o:p> </o:p></p></div></body></html>