Re: Bind dns amplification attack

2023-03-29 Thread Nyamkhand Buluukhuu
Hello guys, I see, my server is authoritative for some internal domain, so I will try Allow-query. Thank you. But the attack is from my allowed IP addresses so I can't block the entire zone. I tried NXDOMAINS-PER-SECOND but server is not giving nxdomain response but servfail. How about

Re: Bind dns amplification attack

2023-03-29 Thread Matus UHLAR - fantomas
On 3/28/23 11:28 AM, Matus UHLAR - fantomas wrote: Yes, this is one of the problem "authoritative zones for local use". On 28.03.23 12:18, Grant Taylor via bind-users wrote: Authorizing the /zone/ for local use wasn't the problem. The problem was that the world could get some of that zone's