Re: DOS attack on DNs

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Thomas Lee (tfl_at_psp.co.uk)
Date: 10/03/04


Date: Sun, 3 Oct 2004 11:09:07 +0100

In message <eWUR4QSqEHA.3896@TK2MSFTNGP15.phx.gbl>, "Vicky Sam]"
<vicky_samant@hotmail.com> writes
>Hi Everybody,
>
>I need one help that if there is dos attack on my live dns server then what
>step should I take.

This will very much depend on the nature of the attack. Some steps to
take include:

1. Hardening the server and it's tcp/ip stack. See the Windows security
guides on line for more details.
2. Ensure your external router and firewalls are setup to get rid of the
worst of the traffic.
3. Add IPSec filters on your DNS server to drop any traffic you
determine is malicous. Dropping a few IP addresses, or address ranges
may make this problem go away.
4. Work with your upstream ISP to stop the traffic before it gets to
you.
5. Consider involving law enforcemen.

> Please explain me in details or there is any documents
>or site where I will get all details about troubleshooting on DNS with all
>senarios.

http://www.google.com/search?q=denial+of+service+attack++DNS&start=0&star
t=0&ie=utf-8&oe=utf-8&client=firefox-a&rls=org.mozilla:en-US:official

or

http://tinyurl.com/6zeqs

will give some details of known attacks.

-- 
Thomas Lee
doctordns@gmail.com


Relevant Pages

  • An Implementation of a Birthday Attack in a DNS Spoofing
    ... An Implementation of a Birthday Attack in a DNS Spoofing. ... In november 2002 Vagner Sacramento discovered that a dns server would reply ... * The DNS Server should allow recursive queries to be performed from you. ... # those are parameters to build the fake responses at layers 3,4,7. ...
    (Bugtraq)
  • Re: Reboot in output from "last":
    ... the logs and get rid of any traces/heads-up of their attack... ... > attack your DNS server through your rpc server, ... chkrootkit's report seems to be good news. ... ran rpm -Vva, but I'm not sure what the output means... ...
    (comp.os.linux.security)
  • Re: Reboot in output from "last":
    ... > some point there was a bug in there, ... even see attack attempts that would only work against Windows ... > So, that was my question: when I see that log message, does ... attack your DNS server through your rpc server, ...
    (comp.os.linux.security)
  • Re: Why is bind important?
    ... > can help also help take over the rest of your network... ... >> DNS server can help them to take over the rest of your network. ... One such "attack" is more of a misconfiguration of the DNS server. ... fire up your web browser and point to www.google.com. ...
    (comp.security.misc)
  • Re: FW: IDS Signature Confidence
    ... It depends upon what type of DOS attack you are trying ... sending a large number of packets so as to overwhelm ... The counter based category of IDS ...
    (Focus-IDS)