[Pdns-users] Queries .domain. Attack to root server?

Federico Olivieri lvrfrc87 at gmail.com
Sun Dec 13 18:14:38 UTC 2015


Maybe is unrelated but I found this article about DNS attack to root server
in the last days

http://thehackernews.com/2015/12/dns-root-servers-ddos-attack.html

For me the problem started last week. Anyone noticed something similar?

Federico

2015-12-13 16:54 GMT+00:00 Federico Olivieri <lvrfrc87 at gmail.com>:

> Yeap, I have enabled the feature and reloaded the conf but I can still see
> the problem. From metronome I can see that all answers are normal answers
> (none is in NXDOMAIN). From DSC graphs I can see more than 100K against
> root-a server just for today.
>
> I'll try to investigate a little bit more and get more details. Thanks
> anyway for your time!
>
> Federico
>
> 2015-12-13 16:42 GMT+00:00 Peter van Dijk <peter.van.dijk at powerdns.com>:
>
>> Hello,
>>
>>
>> On 13 Dec 2015, at 17:15, Stephane Bortzmeyer wrote:
>>
>> On Sun, Dec 13, 2015 at 03:57:17PM +0000,
>>> Federico Olivieri <lvrfrc87 at gmail.com> wrote
>>> a message of 58 lines which said:
>>>
>>> Can you please add more details in your answers?
>>>>
>>>
>>> There are NO requests for names ending in .domain. You do not read
>>> correctly the output of tcpdump.
>>>
>>
>> Stephane is right. This makes my root-mx-trust answer somewhat useless
>> for your question (but the explanation of how it works stands, of course).
>>
>>
>> Kind regards,
>> --
>> Peter van Dijk
>> PowerDNS.COM BV - https://www.powerdns.com/
>>
>> _______________________________________________
>> Pdns-users mailing list
>> Pdns-users at mailman.powerdns.com
>> http://mailman.powerdns.com/mailman/listinfo/pdns-users
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.powerdns.com/pipermail/pdns-users/attachments/20151213/15d42e4b/attachment-0001.html>


More information about the Pdns-users mailing list