Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15912

Re: DNS security, amplification attacks and recursion

From Stephane Bortzmeyer <bortzmeyer@nic.fr>
Newsgroups comp.protocols.dns.bind
Subject Re: DNS security, amplification attacks and recursion
Date 2020-07-07 15:22 +0200
Organization NIC France
Message-ID <mailman.624.1594128113.942.bind-users@lists.isc.org> (permalink)
References <7adcb06a-4d03-7362-6f4a-29b3fb223697@nixmagic.com> <20200707132216.GA30574@nic.fr>

Show all headers | View raw


On Tue, Jul 07, 2020 at 03:00:13PM +0200,
 Michael De Roover <isc@nixmagic.com> wrote 
 a message of 46 lines which said:

> The command used to test this was apparently "dig +short
> test.openresolver.com TXT @your.name.server".

ANY instead of TXT may be more efficient (specially with +dnssec), if
the goal is to get the maximum amplification. Of course, if the server
implements RFC 8482, ANY won't help.

> Authoritative name servers may not need a huge DNS infrastructure
> for a small-ish zone (say under 1k records), but recursors on the
> scale of Google and Cloudflare in particular (not sure how popular
> Quad9 is so far).. those use massive infrastructure including
> anycast and everything! I'd consider it safe to assume that their
> servers are at least on the order of 100Gbps cumulatively, if not
> more.

This is precisely what makes them dangerous. They are good reflectors
(good from the point of view of the attacker). On the other hand, they
typically implement various forms of rate-limiting, and they are
monitored closely by knowledgeable professionals so, they may not be
good reflectors after all.

> If these would be vulnerable to amplification attacks just because
> they allow recursion,

They're not vulnerable, this attack works by reflection (just like the
NTP attack you mentioned) so they are not the potential victims, they
could be used as helpers.


Back to comp.protocols.dns.bind | Previous | Next | Find similar


Thread

Re: DNS security, amplification attacks and recursion Stephane Bortzmeyer <bortzmeyer@nic.fr> - 2020-07-07 15:22 +0200

csiph-web