Recent DNS attacks from China?

Drew Weaver drew.weaver at thenap.com
Wed Nov 30 20:12:09 UTC 2011


-----Original Message-----
From: Rob.Vercouteren at kpn.com [mailto:Rob.Vercouteren at kpn.com] 
Sent: Wednesday, November 30, 2011 3:05 PM
To: MatlockK at exempla.org; richard.barnes at gmail.com; andrew.wallace at rocketmail.com
Cc: nanog at nanog.org; leland at taranta.discpro.org
Subject: RE: Recent DNS attacks from China?

Yes it is, but the problem is that our servers are "attacking" the so called source address. All the answers are going back to the "source". It is huge amplification attacks. (some sort of smurf if you want) The ip addresses are spoofed (We did a capture and saw all different ttl's so coming from behind different hops) And yes we saw the ANY queries for all the domains.

I still wonder how it is still possible that ip addresses can be spoofed nowadays

=================

Rob,

Transit providers can bill for the denial of service traffic and they claim it's too expensive to run URPF because of the extra lookup.

-Drew




More information about the NANOG mailing list