Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Internet's root servers take hit in DDoS attack (Global DNS servers forced offline for hours)
The Register ^ | Dec 8, 2015 | Kieren McCarthy

Posted on 12/09/2015 7:32:50 PM PST by dayglored

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-32 last
To: MrShoop

Ah, I had spoofing confused with using a VPN.


21 posted on 12/09/2015 9:35:11 PM PST by CitizenUSA (Proverbs 14:34 Righteousness exalts a nation, but sin is a disgrace to any people.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Alas Babylon!

Dark Ages 2.0 is descending upon us. Continual warfare and destruction of Mediterranean trade routes took the rise of European civilization off line for hundreds of years. Now the same circumstances have sprung up. In both instances - infighting among the affected parties kept them from fixing the problem.


22 posted on 12/10/2015 2:46:32 AM PST by x_plus_one (The hammer of heretics, the light of Spain, the savior of his country, the honor of his order..)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

For the non-geeks:

Bookmark
209.157.64.200
&
209.157.64.201

Both’ll get you to FR without regard to DNS server problems. As well, you can get to other sites via their IP addresses. Domain Name Servers resolve the web address to the IP. When DNS fails for any reason, websites don’t load but usually will via IP.

This will get other IPs if you don’t know how to use your cmd interface
http://www.ip-tracker.org/

Create a separate folder for all your go-to websites via IPs with the name of the link being the URL and the shortcut address being the IP; it only takes minutes and reduces your reliance on tech that will ultimately fail again and cause you “Not found” or “Error” et al...


23 posted on 12/10/2015 4:31:39 AM PST by logi_cal869 (-cynicus-)
[ Post Reply | Private Reply | To 1 | View Replies]

To: logi_cal869

Thanks!

Fr ip
Bookmark
209.157.64.200
&
209.157.64.201


24 posted on 12/10/2015 4:33:35 AM PST by Covenantor ("Men are ruled-...by liars who passing refuse the. news, and by fools who cannot govern." Chesterton)
[ Post Reply | Private Reply | To 23 | View Replies]

To: dayglored

Interesting timing with the meeting coming up next week. The message is: the only viable defense against a DDoS attack is cooperation and to cut it off before it can get to the intended target. Once your network interfaces are flooded with traffic, there’s not much you can do, the wire/fiber’s bandwidth is full. The only real way to prevent/stop them is distributed just like the attack. Prevent or limit the amount of traffic you’re willing to forward. The anti-spoofing helps because it means you can effectively filter out the bots doing the attack.


25 posted on 12/10/2015 5:43:23 AM PST by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

It’s difficult to protect against a DDoS. There has to be a balance between security and functionality. The root servers are VERY busy and are not actually servers but farms of them. To jam up an entire DNS farm takes a very concerted effort.


26 posted on 12/10/2015 5:51:03 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia
> It's difficult to protect against a DDoS. There has to be a balance between security and functionality. The root servers are VERY busy and are not actually servers but farms of them. To jam up an entire DNS farm takes a very concerted effort.

I've assumed that for at least the last (say) decade, that the root servers are a widely-distributed, load-balanced farm, the sort of thing that supports Google's DNS and website, Wikipedia, Windows Update, and other high-capacity sites. Folks like Akamai have the facilities.

Which is why I found the news item about a successful DDoS against three root servers to be so interesting, and concerning. As you point out, one doesn't pull off a big DDoS without planning and trying very hard.

27 posted on 12/10/2015 6:00:05 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 26 | View Replies]

To: dayglored

Well, you can have the biggest farm of servers on the planet, but if your pipe isn’t very big, it’s pretty simple to clog it with traffic.

The sole US-based root server, the “G” server, is located in Chicago and is in a locked rack in a lights-out datacenter. That means nothing when your ingress points are susceptible to clogging, which I suspect is part of the reason we’ve had these problems.


28 posted on 12/10/2015 6:04:59 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 27 | View Replies]

To: dayglored

China ? Russia ? Iran ? Obama Regime ? Israel? Heretofore unknown hacker group ? White Hats? Black Hats?

29 posted on 12/10/2015 6:07:07 AM PST by csvset ( Illegitimi non carborundum)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

30 posted on 12/10/2015 9:16:20 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: AdmSmith; AnonymousConservative; Berosus; bigheadfred; Bockscar; cardinal4; ColdOne; ...
Remember, and repeat after me, anonymous hackers are really big heroes.

31 posted on 12/12/2015 12:08:46 PM PST by SunkenCiv (Here's to the day the forensics people scrape what's left of Putin off the ceiling of his limo.)
[ Post Reply | Private Reply | View Replies]

To: dayglored
... the internet's root servers as a group weathered this attack, two things are very troubling: It could happen again and bigger, They shouldn't have been that easy to knock offline. So something needs attention, and soon.

An Administration that couldn't create a web page to sell a product like health insurance might not be capable of understanding how important the issue is...

Liberal elites think they're smart because they have "airs, attitudes, and tone"... but little else. They're fools.

These are scary times.

32 posted on 12/12/2015 12:54:28 PM PST by GOPJ (The enemy? (UWEE) Unified Washington Establishment Elites (UWEE -sounds similar to a pig call.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-32 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson