DOS attack against DNS?

Roy garlic at garlic.com
Sun Jan 15 06:45:06 UTC 2006


I just started seeing thousands of DNS queries that look like some sort 
of DOS attack.  One log entry is below with the IP obscured.

client xx.xx.xx.xx#6704: query: z.tn.co.za ANY ANY +E

When you look at z.tn.co.za you see a huge TXT record.

Is anyone else seeing this attack or am I the lucky one?  Is this a 
known attack?

Roy



More information about the NANOG mailing list