Path: csiph.com!news.uzoreto.com!news.etla.org!nntp-feed.chiark.greenend.org.uk!ewrotcd!usenet-its.stanford.edu!usenet.stanford.edu!not-for-mail From: Matus UHLAR - fantomas Newsgroups: comp.protocols.dns.bind Subject: Re: issue of Amplification attack Date: Sun, 12 Jul 2020 14:28:50 +0200 Lines: 22 Approved: bind-users@lists.isc.org Message-ID: References: <675429057.121047.1594527824988.JavaMail.open-xchange@webmail.cdac.in> <4b193b9a-ae4f-a66f-ebe2-3fe0ebfdb843@ghnou.su> <20200712122850.GA8298@fantomas.sk> NNTP-Posting-Host: lists.isc.org Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-2; format=flowed Content-Transfer-Encoding: 8bit X-Trace: usenet.stanford.edu 1594556942 16649 149.20.1.60 (12 Jul 2020 12:29:02 GMT) X-Complaints-To: action@cs.stanford.edu To: bind-users@lists.isc.org Return-Path: X-Original-To: bind-users@lists.isc.org Delivered-To: bind-users@lists.isc.org X-Authentication-Warning: fantomas.fantomas.sk: uhlar set sender to uhlar@fantomas.sk using -f Mail-Followup-To: bind-users@lists.isc.org Content-Disposition: inline In-Reply-To: <4b193b9a-ae4f-a66f-ebe2-3fe0ebfdb843@ghnou.su> User-Agent: Mutt/1.10.1 (2018-07-13) X-Spam-Status: No, score=-0.0 required=5.0 tests=SPF_HELO_PASS,SPF_PASS autolearn=disabled version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mx.pao1.isc.org X-BeenThere: bind-users@lists.isc.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: BIND Users Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Mailman-Original-Message-ID: <20200712122850.GA8298@fantomas.sk> X-Mailman-Original-References: <675429057.121047.1594527824988.JavaMail.open-xchange@webmail.cdac.in> <4b193b9a-ae4f-a66f-ebe2-3fe0ebfdb843@ghnou.su> Xref: csiph.com comp.protocols.dns.bind:15972 >On 7/12/20 6:23 AM, ShubhamGoyal wrote: >>                         Thank you  for give me answer for my >>previous question,  Sir now we are suffer from amplification attack >>so is there any method in bind to stop DNS Amplification attack. >>I am thinking to stop or drop ANY type queries from our DNS >>Recursive resolver , so please tell me how can we drop or stop ANY >>type queries from bind. On 12.07.20 12:48, Michael De Roover wrote: >There was a very interesting conversation about this last week. See >https://www.mail-archive.com/bind-users@lists.isc.org/msg29187.html. alternative link: https://lists.isc.org/pipermail/bind-users/2020-July/103389.html I find it more readable. -- Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etry, (A)bort, (C)ancer