nanog mailing list archives

Re: DNS Amplification attack?


From: Chris Adams <cmadams () hiwaay net>
Date: Tue, 20 Jan 2009 21:17:50 -0600

Once upon a time, jay () miscreant org <jay () miscreant org> said:
I've also noticed that on a server running BIND 9.3.4-P1 with  
recursion disabled, they're still appear to be getting the list of  
root NS's from cache, which is a 272-byte response to a 61-byte  
request, which by my definition is an amplification.

Add "additional-from-cache no;" to the options{} section of your
named.conf.
-- 
Chris Adams <cmadams () hiwaay net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.


Current thread: