DDoS against a public DNS blacklist
Summary
Manuel Schmitt reports on a DDoS attack on ix.dnsbl.manitu.net and then considers a list of permitted query networks. ix.dnsbl.manitu.net was hit by a DDoS attack in June 2007. Bert Ungerer and Manuel discussed operating on a whitelist basis.
Ideas
- DNS-based blocklists are themselves attractive targets for the spammers they list.
- A query whitelist reduces the attack surface but limits the open benefit.
- With DNSBL queries, the visible source is often the recursive resolver and not the mail server.
Insights
- Abuse protection can gradually turn an open community service into a closed one.
- With DNS, source address models must distinguish between application and resolver.
Facts
- Interested parties were asked to report the IP addresses of their querying DNS resolvers.
Recommendations
- Protect authoritative DNS services with anycast, rate limits and several independent locations.
- When using access controls, document which resolver addresses customers need to have approved.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.