Attack on the DNS ?

2012-03-31 Thread Marshall Eubanks
Anyone seen signs of this attack actually occurring ? http://www.nytimes.com/2012/03/31/technology/with-advance-warning-bracing-for-attack-on-internet-by-anonymous.html?_r=1 The message called it Operation Global Blackout, and rallied Anonymous supporters worldwide to attack the Domain Name Syst

Re: Attack on the DNS ?

2012-03-31 Thread sthaug
> Anyone seen signs of this attack actually occurring ? > > http://www.nytimes.com/2012/03/31/technology/with-advance-warning-bracing-for-attack-on-internet-by-anonymous.html?_r=1 >From my vantage point in Oslo, Norway, there is no sign of any attack occurring. Steinar Haug, Nethelp consulting,

Re: Attack on the DNS ?

2012-03-31 Thread Stephane Bortzmeyer
On Sat, Mar 31, 2012 at 05:05:46AM -0400, Marshall Eubanks wrote a message of 17 lines which said: > Anyone seen signs of this attack actually occurring ? For serious information about this issue, see: https://www.dns-oarc.net/wiki/mitigating-dns-denial-of-service-attacks http://www.cricketo

Re: Attack on the DNS ?

2012-03-31 Thread Adrian Minta
We already have this type of attack in Bucharest/Romania since last Friday. The targets where IP's of some local webhosters, but at one moment we event saw IP's from Go Daddy. Tcpdump will show something like: 11:10:41.447079 IP target > open_resolver_ip.53: 80+ [1au] ANY? isc.org. (37) 11:10:4

Re: Attack on the DNS ?

2012-03-31 Thread Valdis . Kletnieks
On Sat, 31 Mar 2012 05:05:46 -0400, Marshall Eubanks said: > Anyone seen signs of this attack actually occurring ? > > http://www.nytimes.com/2012/03/31/technology/with-advance-warning-bracing-for-attack-on-internet-by-anonymous.html?_r=1 "Those preparations turned into a fast-track, multimillio

Re: Attack on the DNS ?

2012-03-31 Thread sthaug
> We already have this type of attack in Bucharest/Romania since last > Friday. The targets where IP's of some local webhosters, but at one > moment we event saw IP's from Go Daddy. > Tcpdump will show something like: > 11:10:41.447079 IP target > open_resolver_ip.53: 80+ [1au] ANY? isc.org. > (

Re: Attack on the DNS ?

2012-03-31 Thread Lamar Owen
On Saturday, March 31, 2012 04:28:17 PM sth...@nethelp.no wrote: > ANY queries for isc.org and ripe.net are popular (ietf.org has also been > seen), since they give a potentially large amplification factor. FWIW, saw ANY queries at a rate of 10 per second from one IP to a DNS server today, all fo

Re: Attack on the DNS ?

2012-03-31 Thread Greg Ihnen
I manage a tiny network in the Amazon, a satellite internet connection and decent sized wireless network. All of my users started complaining yesterday about lost connectivity except for Skype. I had no problems. I checked from the users' computers and could not resolve domain names (when Skyp

Re: Attack on the DNS ?

2012-03-31 Thread Greg Ihnen
I manage a tiny network in the Amazon, a satellite internet connection and decent sized wireless network. All of my users started complaining yesterday about lost connectivity except for Skype. I had no problems. I checked from the users' computers and could not resolve domain names (when Skyp

Re: Attack on the DNS ?

2012-03-31 Thread Greg Ihnen
I manage a tiny network in the Amazon, a satellite internet connection and decent sized wireless network. All of my users started complaining yesterday about lost connectivity except for Skype. I had no problems. I checked from the users' computers and could not resolve domain names (when Skyp

Re: Attack on the DNS ?

2012-03-31 Thread Ameen Pishdadi
Looks like your network has a user or two participating in this retarded attempt to drop the Internet. Thanks, Ameen Pishdadi On Mar 31, 2012, at 8:30 PM, Greg Ihnen wrote: > I manage a tiny network in the Amazon, a satellite internet connection and > decent sized wireless network. > > All

Re: Attack on the DNS ?

2012-04-01 Thread Rubens Kuhl
On Sat, Mar 31, 2012 at 10:09 PM, Greg Ihnen wrote: > I manage a tiny network in the Amazon, a satellite internet connection and > decent sized wireless network. > Is DNS traffic being directed to bogus servers? Are the real servers being > overloaded? Am I seeing the results of some kind of DD