4 ms·
Interesting. DNS reflection is one I hadn't heard about before. Very interesting.
by superkvn 14y ago
Interesting. DNS reflection is one I hadn't heard about before. Very interesting.
- krakensden 14y agoDJB gave a presentation on it like... last week. Quick turnaround time on the part of the botnet herders.
- jwegan 14y agoDNS reflection has been known (and used) for years. That is why cloudflare mentions there has been an ongoing effort to clean up open resolvers.
- count 14y agoWas that the bit about amplification via DNSSEC?
- ibotty 14y agoi'm pretty sure it was. but he has been telling the world about dnssec amplification for years now, so this is hardly news.
- belorn 14y agoThe amplification is by asking the misconfigured resolver about a DNSSEC zone. Basically, DNSSEC just mean you do not need to search the for a large zone to request. Given that large zones are not directly in shot supply, and that searching for them is (in the age of ipv4) rather easy, I wonder if DNSSEC actually have any affect on the issue what so ever.
- smountcastle 14y agoDNSSEC-signed responses can be very large. Here's an example of turning a 31 byte request into a 3974 byte response: http://dnscurve.org/amplification.html http://dnscurve.org/amplification.html That's ~128x amplification -- with a 100Mbps connection, roughly 12.8Gbps of responses would be sent to the forged IP source.
- udpheaders 14y agoYet another reason DNSSEC is more trouble than it's worth. It's a gift to anyone wanting to do this type of DDOS.