2 ms·
I encountered a DNS Amplification attack recently and was confused how the VM I was using could be involved given it wasn't running BIND. It turned out that a
by follower 14y ago
I encountered a DNS Amplification attack recently and was confused how the VM I was using could be involved given it wasn't running BIND.
It turned out that a VPN was implemented using `dnsmasq` which was responding to the DNS queries.
I ended up using firewall rules to drop the queries because it seems like in certain situations it's not enough to just configure `dnsmasq` to not respond to the requests: http://people.canonical.com/~ubuntu-security/cve/2012/CVE-2012-3411.html http://people.canonical.com/~ubuntu-security/cve/2012/CVE-20...
Just incase the information is useful to anyone else. :)
(I Am Not A Network Engineer.)