4 ms·
Another reminder: If you're running DNS servers, make sure you are not providing recursion: http://openresolverproject.org/ http://openresolverproject.org/
by devicenull 13y ago
Another reminder: If you're running DNS servers, make sure you are not providing recursion: http://openresolverproject.org/ http://openresolverproject.org/
- marshray 13y agoHad dnsimple failed to do so? Did it help? Because Easydns http://blog.easydns.org/2013/06/04/post-mortem-of-the-june-3-4th-ddos/ http://blog.easydns.org/2013/06/04/post-mortem-of-the-june-3... said "While most of these typically use open resolvers, it is also now common to use authoritative nameservers in reflection attacks". Can we end the "War on 'Open' Internet (Resolvers)" now? Because I don't think an organized crackdown on "open" authoritative nameservers is in the best interests of our freedom.
- aeden 13y agoNo, this was not due to open resolvers in this case. We do not run public resolvers - we only provide authoritative DNS.
- devicenull 13y agoWe can end the war on open revolvers when we stop getting hit with multi-gigabit DDOS attacks from open revolvers.