3 ms·
Cloudflare killed "ANY?" because it was a significant vector in DNS amplification attacks. Ironically enough, avoiding the "expensive" query type resulted in p
by kees99 7y ago
Cloudflare killed "ANY?" because it was a significant vector in DNS amplification attacks.
Ironically enough, avoiding the "expensive" query type resulted in potentially doubling the amount of DNS traffic from a typical dual-stack client ("A?" + "AAAA?" instead of single "ANY?")
EDIT: ...or warranted adding laggy heuristics that eventually settles into either, as Avamander points out below.
- Avamander 7y agoI heavily doubt it's doubling, what I've seen is that double-stack software falls back to one or the other.
- zamadatix 7y agoSeems to be the case: https://i.imgur.com/ACfFQwN.png https://i.imgur.com/ACfFQwN.png Edit: Also seems to still be the case when you have your resolver set to a v6 address.
- belorn 7y agoIt would surprise me if cloudflare relied on blocking "ANY" for DDOS mitigation. Most modern resolver have builtin response rate limiting, and I would expect cloudflare to have multiple additional mitigation methods to prevent malicious actors from exploiting their servers.
- kees99 7y agoIn a DNS-amplified DDoS attack, target (CF for example) would be on the receiving end (right-hand side of [1]), and blocking, while necessary, would not be terribly efficient there. On the other hand, deprecating "ANY" requests as standard, once percolated into BIND and other resolvers, would cut the attack[2] on the amplification stage (middle of the picture of [1]). [1] https://www.cloudflare.com/img/learning/ddos/dns-amplification-ddos-attack/dns-amplification-attack-1.png https://www.cloudflare.com/img/learning/ddos/dns-amplificati... [2] or at least significantly decrease choice and depth of large amplification factor requests available to the attacker.
- teddyh 7y ago> Cloudflare killed "ANY?" because it was a significant vector in DNS amplification attacks. No, they explicitly say it was “too expensive”. The traffic amplification excuse is why they got away with doing it – they, themselves, do not benefit from that aspect. Note that most other DNS vendors in the world has kept ANY queries. Cloudflare removed ANY queries because it does not fit their data model of what DNS is, and faking the correct reply to ANY queries as the standard DNS data model would require would be hard for them, since they don’t operate that way, and they don’t see DNS like that.