Re: Bind-dlz-testers Digest, Vol 28, Issue 1

"Mfoxx" <[email protected]> Mon, 16 Mar 2009 07:27:15 -0500
Newsgroups gmane.network.dns.bind9.dlz
Message-ID <08AEF39856054789B95B3F045744A974@krypton>
Todd-
Thank you for your help. I had looked but hadn't found good info about the 
logging directive. When I implemented it as you suggested, it does indeed 
give me exactly the info I need to figure out the IP of an 'attack' and shut 
them down. I don't leave it on all the time, as its excessive logging for 
normal behavior, but if I see a spike in traffic, I can turn it on quickly 
and determine the source.

I installed iptables and configured it. However, I'm not sure if it works as 
I would hope for DNS traffic. My thought is that perhaps (because of Bind 
security reasons), the port is different. I set up the rules on port 53, and 
set them fairly low to make sure to catch these dns-hogs, but still the 
attacks continued (so obviously the ipchains rules didn't really catch). It 
looked like from the logging that what was happening is that each request 
comes in through different random port numbers (it may globally come in as 
port 53, but I think it processes as a request through the random port 
numbers).

Does anyone have any thoughts or ideas on this?

--Kyle




----------------------------------------------------------------------
Message: 2
Date: Wed, 18 Feb 2009 09:58:01 -0800
From: Todd Lyons <[email protected]>
Subject: Re: [Bind-dlz-testers] Question about DNS blackhole'ing
To: [email protected]
Message-ID:
<[email protected]>
Content-Type: text/plain; charset=ISO-8859-1

On Wed, Feb 18, 2009 at 4:58 AM, Mfoxx
<[email protected]> wrote:
> OK, I have a question, it's not exactly specific to DLZ usage (although a
> solution may come from the fact that I have DLZ installed).
>
> I've got a BIND 9.4 server with DLZ (mysql) running on my server, and
> everything is great. This runs on a debian etch server, so I just have the
> debian packages installed.
>
> However, about once a week or so, my DNS server gets pounded by some 
> foreign
> (russian, I believe) server with a ton of port 53 DNS traffic. It's all
> invalid traffic, for lame servers that I've never had, etc. The problem 
> is,
> the traffic continues unabated for sometimes days on end, constant, which
> drives up my bandwidth costs.  I have on several occasions in the past 
> asked
> my data center host to tell me from the router logs where all the traffic 
> is
> coming from, and they've been able to show me which IP it is that is
> pounding my DNS server. I then immediately add that IP to my blackhole 
> list
> in the BIND configuration, and the traffic completely drops off.
>
> Of all the various services I have on my box, DNS seems to be the only one
> I've not found a good solution to how to have server logs which tell me 
> what
> is being accessed, and more specifically, WHO is doing it (similar to mail
> or apache logs).

Do the logging{} directives not give you the information you want?
The below lines tell me what IP is asking for what in query.log, and
regular messages in named.log:

logging {
        channel logfile {
                file "/var/log/named.log";
                severity info;
                print-time yes; print-category yes; print-severity yes;
                };
        channel query_log {
                file "/var/log/query.log";
                severity info;
                print-time yes; print-category yes; print-severity yes;
                };
        category queries { query_log; };
        category default { logfile; };
        category lame-servers{ null; };
};

> What I would like is a way to have all the DNS connections logged in some
> way, so that I could (without bothering my data center host) find out 
> which
> IP is hitting my server. Another idea (even better) would be if BIND had
> some way to automatically throttle or black-hole an IP if it has too many
> DNS hits within a certain small amount of time. I know mail servers have
> this, and also I think apache. But I've never found anything like this for
> BIND.
>
> Does anyone have any ideas on what I could do? Perhaps I could build into 
> my
> mysql DLZ queries some sort of mysql-based logging of the requesting IP? 
> I
> dunno, but I just REALLY need to find a way to solve this. Any help would 
> be
> greatly appreciated.

Use iptables rate limiting:

http://www.debian-administration.org/articles/187
http://www.geocities.com/youssef116/writing/ratelim.html

The really nice thing about the Debian article is that you can set a
generic rule for port 53 that will automatically match and drop
packets when a host sends more than X new connections per INTERVAL
(seconds, minutes, hours, etc).

The geocities page also mentions a LOG target so that you can _see_
when it actually does it (will be in kernel dmesg output and usually
some log file in /var/log/ ).

-- 
Regards...      Todd
All truth passes through three stages. First, it is ridiculed. Second,
it is violently opposed. Third, it is accepted as being self-evident.
 



------------------------------------------------------------------------------
Apps built with the Adobe(R) Flex(R) framework and Flex Builder(TM) are
powering Web 2.0 with engaging, cross-platform capabilities. Quickly and
easily build your RIAs with Flex Builder, the Eclipse(TM)based development
software that enables intelligent coding and step-through debugging.
Download the free 60 day trial. http://p.sf.net/sfu/www-adobe-com