RE: DDoS update - tomorrow Jan 30 makes this 4 weeksinto the attack
"David McCall" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
> You might see a reduction in the volume of queries were you to change the $TTL from 30 minutes to 30 days. Dang, slap me in the head...all that moving around of the domain to different servers and IP addresses and when we finally got it to a good home, where it now appears to be fairly well protected....... Thanks, I've just made the change back to a week.... >Have you considered the possibility that the increase in DNS traffic is >the result of an MPECLLC.COM system being compromised? You would expect >to see an increase in DNS traffic from systems running tcpwrappers. can't be the system because the domain has moved to many systems, with different physical locations as well as different IP addresses...made no difference. the DDoS slowly returned to the domain at it's new location and began to start all over again.... This behavior is the first real "potentially" globally treatening in terms of wat the attack could do to the bandwidth if instead of just 20-30 domains it had cousins that each containted a 100 or more, and there could be multiple C&C botnet agents feeding from 100's of places.... I mean who would want to DDoS one of the least visited web sites in the entire world, unless this was just a prototype hack to begin to measure propigation and other fallout. I worry that somewhere someone is sitting in their kitchen attempting to code a very dirty nuke outta this one. David C. McCall UNIX Administrator =================== [email protected] [email protected] _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions