A deep look at BIND9 CVE-2015-5477
blog.cloudflare.com
blog.cloudflare.com
This approach is not recommended by legal professionals.
Morally right in an if-someone-tires-to-kill-you-kill-them-right-back way? Certainly legally wrong since most of the participants in these attacks are misconfigured "innocent" 3rd parties, not hostile entities themselves.
The problem is the internet can't handle that much bandwidth at once. While every Open DNS Resolver would crash, so would the whole internet :P
If that is one of the following (or higher), you are save: 9.10.2-P3, 9.9.7-P2, 9.9.5-3ubuntu0.4, 9.8.1.P1-4ubuntu0.12, 9.9.5-4.3ubuntu0.3, 9.9.5-9ubuntu0.2, 9.9.4-18.el7_1.3, 9.8.2-0.37.rc1.el6_7.2, 9.3.6-25.P1.el5_11.3, 9.7.0-21.P2.el5_11.2, 9.8.4.P1-6+nmu2+deb7u2~bpo60+1, 9.7.3-1~squeeze16, 9.8.4.P1-6+nmu2+deb7u6, 9.9.5-9+deb8u2, 9.9.5-11
Ofcourse everything is easier if automated, so that is exactly what following page does: https://scan.patrolserver.com/bind/CVE-2015-5477