Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.

View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
1741 posts

Uber Geek
+1 received by user: 149

Trusted
Subscriber

  Reply # 711375 3-Nov-2012 14:01 Send private message

Cloudflare had an interesting article on something similar a few days ago:

http://blog.cloudflare.com/deep-inside-a-dns-amplification-ddos-attack



75 posts

Master Geek


  Reply # 711376 3-Nov-2012 14:07 Send private message

insane: Cloudflare had an interesting article on something similar a few days ago:

http://blog.cloudflare.com/deep-inside-a-dns-amplification-ddos-attack


Well that's interesting considering the IP I was hitting is a Cloudfare one. Cheers for the link.

BDFL
47987 posts

Uber Geek
+1 received by user: 3557

Administrator
Trusted
Geekzone
Subscriber

  Reply # 711380 3-Nov-2012 14:16 Send private message

I was just going to post about this. Just going back to the OP post:


mattie47: This is probably a pretty grey area, and probably something ISPs normally wouldn't have to deal with, other than customers ringing up complaining about why their data usage is through the roof when they haven't been doing anything.



mattie47:
mattie47: I also have an internal DNS server, but port 53 isn't forwarded from the firewall.


Wow I take that back. I was looking at my port forwarding rules which didn't show 53 anywhere so presumed was closed. I just did a capture on the internal NIC which showed the same traffic. This got me worried. A quick online port check showed 53 as open (what?).

Having a look again around PFSense showed there's a DNS forwarder page I must have skimmed over. Turns out I had "Enable DNS forwarder" ticked. Okay, that's port 53 traffic going to internal now dropped...


Now, a couple of comments, and please don't take it personally...

When running a network service the admin should not "skim over". Any open port with forward traffic may attract unsolicited "visitors". If the service is somehow valuable for them they will use it.

In this situation the service on port 53 can be easily used for a DDoS attack. Even if you don't have an infected computer in your network your devices are still active participants in attacks by simply offering the services and acting on requests from unauthorised users. That's the point above with the link to the DNS amplification attack as described by CloudFlare.

In this case I have to say Slingshot was REALLY NICE to you. The usage was not an error in their systems and they should have every right to charge your account for that. I'm pretty sure in their T&Cs somewhere there'll be a clause saying you're responsible for keeping your connection safe - that means not only safe from malware, but safe from unauthorised access and usage. Running a service and leaving it open it's not their problem, really.

That blog you link in the OP... That guy didn't get the "amplification" part of the attack. He seems to think the attack is directed at him, not at the response from his DNS to the spoofed IP.

Go read the Cloudflare blog again. Secure your network. Make sure to use an external scanner to identify any open ports/active services still lurking (Try GRC ShieldsUP!.

Changing IP addresses without making sure your vulnerabilities aren't protect won't save your bandwidth, as those idiots will find your network again pretty soon - port scanners are capable of going around entire IP blocks very quickly.








2863 posts

Uber Geek
+1 received by user: 131

Trusted
Subscriber

  Reply # 711695 4-Nov-2012 12:09 Send private message

Hi Mattie,
Looking at your PFsense rules you have an allow all on the WAN. The way firewall rules work on PFsense is that the first rule it find that matches is applied. So the rules you have underneath that don't count at all. It definitely sounds like you are thus being used as an open relay.

What you should do is delete that first rule for allow all. Put your allow rules in place e.g. RDP, HTTP etc. then put a deny all underneath those.


Also, I believe because you are using private address space for your LAN, you should set your destination for the allow rules to be your WAN interface rather than 192.168.XX.XX.





1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic








Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Telecom introduces unlimited broadband data plan
Created by freitasm, last reply by NonprayingMantis on 23-Apr-2014 23:13 (93 replies)
Pages... 5 6 7


Stonedine
Created by Lizard1977, last reply by surfisup1000 on 23-Apr-2014 21:27 (58 replies)
Pages... 2 3 4


Telecom has started metering their TiVo customers' broadband usage (WITHOUT PRENOTIFICATION)
Created by Peteriv, last reply by mxpress on 23-Apr-2014 14:22 (69 replies)
Pages... 3 4 5


Forms of government for New Zealand
Created by charsleysa, last reply by KiwiNZ on 23-Apr-2014 20:57 (169 replies)
Pages... 10 11 12


Parallel imported product
Created by Wills1, last reply by joker97 on 23-Apr-2014 21:01 (53 replies)
Pages... 2 3 4


MH370 - Call for Search & Rescue Help
Created by DS248, last reply by joker97 on 23-Apr-2014 22:37 (737 replies)
Pages... 48 49 50


Labour MP Shane Jones to step down
Created by jeffnz, last reply by jeffnz on 23-Apr-2014 20:41 (32 replies)
Pages... 2 3


Upcoming Freeview Restack AUCKLAND
Created by Brunzy, last reply by richms on 23-Apr-2014 21:05 (13 replies)


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.