bk99.de entertain the web since 1997

DDoS against a public DNS blacklist

Summary

Manuel Schmitt reports on a DDoS attack on ix.dnsbl.manitu.net and then considers a list of permitted query networks. ix.dnsbl.manitu.net was hit by a DDoS attack in June 2007. Bert Ungerer and Manuel discussed operating on a whitelist basis.

Ideas

  • DNS-based blocklists are themselves attractive targets for the spammers they list.
  • A query whitelist reduces the attack surface but limits the open benefit.
  • With DNSBL queries, the visible source is often the recursive resolver and not the mail server.

Insights

  • Abuse protection can gradually turn an open community service into a closed one.
  • With DNS, source address models must distinguish between application and resolver.

Facts

  • Interested parties were asked to report the IP addresses of their querying DNS resolvers.

Recommendations

  • Protect authoritative DNS services with anycast, rate limits and several independent locations.
  • When using access controls, document which resolver addresses customers need to have approved.

References

Read the original article on Hostblogger

Search the Web Archive