Re: Non-existent zone file
Peter Pentchev <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Dec 03, 2009 at 11:36:55AM -0600, Charles Cazabon wrote: > Rich Rumble <[email protected]> wrote: > > We run djbdns, and recently someone sent a huge spam campaign using a > > domain we did not have a zone file for. We also did not register the > > domain, but whoever did pointed it at our NS's and we were quickly > > DDoS'd for a short amount of time > > Okay. DDoS attacks suck, but IP doesn't really provide a way to prevent them. > > > until we created a dummy zone file for said domain. > > Can you clarify what you mean? tinydns doesn't answer queries for domains > that you haven't configured it to answer for -- it just drops the queries on > the floor. Adding a "dummy zone file" (tinydns doesn't use zone files, just a > single data file compiled to cdb format) for the domain should only have made > things worse, as you would then start answering queries for that domain. As others pointed out, if tinydns drops the query, the remote caches will simply retry later, sometimes in a matter of seconds. If tinydns returns NXDOMAIN, the remote caches will abstain from asking again for the duration of the negative-TTL value in the SOA record. Thus, a short answer will prevent many more requests for a non-trivial amount of time :) G'luck, Peter -- Peter Pentchev [email protected] [email protected] [email protected] PGP key: http://people.FreeBSD.org/~roam/roam.key.asc Key fingerprint 2EE7 A7A5 17FC 124C F115 C354 651E EFB0 2527 DF13 This sentence contradicts itself - or rather - well, no, actually it doesn't!
signature.asc
(application/pgp-signature, 834 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.13 (FreeBSD) iQIcBAEBCgAGBQJLGTcPAAoJEGUe77AlJ98T1ksQAK5ac1K7c0n93hcNHSLDljeN 6sqSOHDfyLnoCPOPkIl5xG6XGfHNghKEbD6G2B2j7SkcQBMbTPvFxj6acgWhShnx l7gtQlzx6mgBICQ0BqzDTlIZmnUnxU0penJgJ/18T2vWaunHmXKHuEgILTYS09Vb fKVYHyHgJ7LXLjbFGmTTjMttYBxUo8fMKO5AlsigrUIgJpH793m/1CHwLtKDYnzk vSzGk723NBWQnlz2pC/LlgMkQcmFWJdnV5RiEi4DR36iKcymSSvPLE1GSYoKbzyj FAFB7dYvd43m33E6w1tOq6zOIhfhkK32VwqS6jNOR2ZOF5mcEa0eqjiMSwAZH2IP oWyNmQOEPlRB67QLxPitmdqpf780aGmA4FD2Ma9M5lEnPudb/P8IwKWyUgnp9bqv aQA0kUtE53YY6ikm8ld5BbqUSHT06tIEIi077xQTpx3DSPkwNH9O3+UK3DaLYkLT dlM5/hX6gxDCmkbIPvqX/pgophem/SInaHuG9Yz8yIUlQcJ9CJcMZnZ3F/qORi+8 VYFRG3aPFe5reX/gJdfhl8XRD49iu2KPm6e33sYjqUyTcdhZY6qoG6AB2cpe8iZs 1HApMgCTlocUTQZ09VD/9ekN/RSnSAq1Q/Pap2WMsnMezS9dj9jLIO+XG+APYpJg /tzuBt2yjT0CEBkGvhyE =vTvS -----END PGP SIGNATURE-----