DNS with Akamai

Etaoin Shrdlu shrdlu at deaddrop.org
Sat Jul 10 04:42:45 UTC 2004


joe wrote:
> 
> Anyone noticing issues with Akamai and their DNS stuff?
> Just wondering because I'm seeing strange responses regarding
> www.foxnews.com, in that one of the Cnames a20.g.akamai.com
> is changing every 20 seconds, and sometimes no response at all.

It's really too soon to tell, but there is certainly something out there
aimed right at the root servers. I saw a post from someone on full
disclosure claiming that there was a 0-day exploit against bind (although
the version wasn't named). There was huge activity for about four hours,
but it leveled off about 20-30 minutes ago. I'm still analyzing earlier
ethereal dumps, and logs, looking for the injection, or other evidence.

Some of this would probably explain any anomalies you see at akamai.

--
...because as an industry we've tried to make security seem easier
than it actually is. We want to make it like driving a car when it's
more like flying an airplane.
             Chris Brenton (at 08:22 -0400 19 Apr 2004 on NANOG)



More information about the NANOG mailing list