Slow Service Early Wednesday Morning (1-4AM)

What's Up With Eskimo's Community!

Moderators: Nanook, carl

Post Reply
User avatar
Posting Freak
Posts: 347
Joined: Tue Jun 25, 2013 10:08 pm
Location: Shoreline

Slow Service Early Wednesday Morning (1-4AM)

Post by Nanook » Wed Sep 12, 2018 4:38 am

Slow service early this morning and the temporary unavailability of was the result of a denial of service attack where upon our name servers were used as amplifiers in a denial of service attack aimed at us. I had to lower the external view rate limit because of this, hopefully it is still adequate to service legitimate requests.

There are aspects of this attack that I do not understand. They forged an address of from outside (udp packets so no three-way connect) and directed requests at, so our name servers would attempt to reply to but there was no host on that IP address and the result was that our router didn’t know what to do with it and it overloaded it logging what it considered “Martian” packets.

The puzzling aspect of this is I have a firewall rule that SHOULD block all traffic from an external interface which has an internal address. I was able to mitigate the attack by blackholeing at the name servers and rate limiting responses.

Post Reply

Who is online

Users browsing this forum: No registered users and 59 guests