Attack on the DNS ?

Rubens Kuhl rubensk at
Sun Apr 1 11:56:51 UTC 2012

On Sat, Mar 31, 2012 at 10:09 PM, Greg Ihnen <os10rules at> wrote:
> I manage a tiny network in the Amazon, a satellite internet connection and decent sized wireless network.

> Is DNS traffic being directed to bogus servers? Are the real servers being overloaded? Am I seeing the results of some kind of DDOS mitigation technique?

If you are using broadband connection from the brazilian incumbent
operator (Oi), you might indeed being redirected to bogus servers.
They are very fond of "monetizing" techniques with their user base,
using either DNS or all the traffic for that matter (Phorm).


More information about the NANOG mailing list