Forgot your password?
typodupeerror
Networking

Misconfigured Open DNS Resolvers Key To Massive DDoS Attacks 179

Posted by Unknown Lamer
from the check-your-sources dept.
msm1267 writes with an excerpt From Threat Post: "While the big traffic numbers and the spat between Spamhaus and illicit webhost Cyberbunker are grabbing big headlines, the underlying and percolating issue at play here has to do with the open DNS resolvers being used to DDoS the spam-fighters from Switzerland. Open resolvers do not authenticate a packet-sender's IP address before a DNS reply is sent back. Therefore, an attacker that is able to spoof a victim's IP address can have a DNS request bombard the victim with a 100-to-1 ratio of traffic coming back to them versus what was requested. DNS amplification attacks such as these have been used lately by hacktivists, extortionists and blacklisted webhosts to great success." Running an open DNS resolver isn't itself always a problem, but it looks like people are enabling neither source address verification nor rate limiting.

Comment: Re:Don't raise taxes (Score 3, Insightful) 427

by wmbetts (#42670233) Attached to: Tech Firms Keep Piles of 'Foreign Cash' In US

In a senario like that the wealthy would be safe, because they could afford a private police force. They middle class neighborhoods would be safe, because they as a whole (neighborhoods setup with stuff like HOAs) could afford a private police force. Poor neighborhoods would be more than likely ran by some sort of gang (a lot are even now).

Your mode of life will be changed to EBCDIC.

Working...