Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
DNS "attack"
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Broadband
- :
- DNS "attack"
DNS "attack"
02-08-2013 5:06 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
For the last couple of days, I've been seeing a lot of UDP packets originating on port 53 hitting my IP address. Because of the port number, I'm guessing that they are DNS replies which are responding to spoofed requests.
That's a well-known mechanism for a denial-of-service attack (look up "DNS Amplification") but in this case there are only 20 or so per minute, hardly a brutal attack.
I've just checked the Plusnet firewall to see if there was any way to filter, but it seems not. I suppose that was optimistic anyway, since the firewall would have to be able to distinguish unsolicited DNS replies from real ones.
I'm not being inconvenienced by this at all, but I was wondering if it's happening widely. Anyone else seeing it?
That's a well-known mechanism for a denial-of-service attack (look up "DNS Amplification") but in this case there are only 20 or so per minute, hardly a brutal attack.
I've just checked the Plusnet firewall to see if there was any way to filter, but it seems not. I suppose that was optimistic anyway, since the firewall would have to be able to distinguish unsolicited DNS replies from real ones.
I'm not being inconvenienced by this at all, but I was wondering if it's happening widely. Anyone else seeing it?
Message 1 of 3
(701 Views)
2 REPLIES 2
Re: DNS "attack"
02-08-2013 6:12 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
No I haven't noticed anything, although I had stopped recording stats and log messages for most of this week until yesterday.
Message 2 of 3
(364 Views)
Re: DNS "attack"
02-08-2013 8:32 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Not seeing anything on my end, perhaps provide some of the IPs and it can be looked in to. Should be easy enough to check if there's a vulnerable DNS server running.
Message 3 of 3
(364 Views)
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page