Also, http://openresolverproject.org
PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...
Also, http://openresolverproject.org
PS Technical details: http://blog.cloudflare.com/the-ddos-that-almost-broke-the-in...
See poorly configured DNS servers and ISP's failing to configure their networks properly - so traffic with a source address which is not part of your allocated IP block is not allowed to leave your network. It is not that hard!
The Internet Infrastructure is working as designed.
Ref:
http://en.wikipedia.org/wiki/Ingress_filtering
http://tools.ietf.org/html/bcp38
Also:
If you run a DNS server - it is your responsibility to maintain and protect it so that it cannot be used to attack others, and by doing that you are helping the 'Internet infrastructure' remain intact as designed. By not doing this you are helping the 'attackers'
It may not be that hard to set things up this way, but very few ISPs configure their network with this restriction.
BCP 38, RFC 2827, is designed to limit the impact of distributed
denial of service attacks, by denying traffic with spoofed addresses
access to the network,If Spamhaus' Linford is quoted accurately, he's kind of full of it. The NYT article gives more detail about CloudFlare's involvement.
Not just for the awesome read but this seems like a data point for the global internet. Very much of interest.
It has an actual location. The name of the owner is known. It has evidentially been involved in legal disputes so it is on record with the government.
Much more likely is someone using the hosting system for something nefarious is retaliating against spamhaus. I don't think the hosting company should go down for that.
I abhore censorship. Does Spamhause engage in it?
From what I understand, Spamhaus basically provides lists that identify known spammers, or known spam hosts. These lists are used for things like filtering out spam emails. So Spamhaus is basically saying that Cyberbunker is a host to spammers, and therefore email coming from the Cyberbunker's IP addresses should be treated as spam.
Spamhaus isn't preventing anyone from putting anything anywhere, they provide a service that others can use so they don't have to see it.
This post in no way is a comment on any of Spanhaus' practices which has garnered some criticism.
AIUI, as mhurron says, what Spamhaus does is publish a list.
The nominal purpose of that list is to identify spammers, so that people who wish to filter out spam can be assisted by that. People do, in fact, use that list, to filter email. The email recipient wants to be protected from spam, so the recipient's ISP attempts to perform that service, and Spamhaus contributes an opinion that the ISP takes seriously.
So, in practice, if Spamhaus adds you to their list, many many users will stop seeing email from you. Spamhaus has a great deal of power to mostly-silence domains.
I have no reason to believe that Spamhaus uses their power for anything other than good. But it's not quite as simple as "do they censor? no".
In CRAs' own opinions, they are practicing "free speech" and giving what amounts to "numeric editorials on the quality of companies." In critics' opinions, large corporations and sometimes governments are relying on these "editorials", so CRAs' abilities to say whatever-the-heck-they-want should be regulated.
That being said, the problem with many BL's is that they are run by incompetents or extremists. They usually either end up blocking things that are not spam by accident (see lists of supposedly dynamic IPs), or block whole subnets (sometimes entire ISPs) to try and "teach them a lesson." or blackmail them into fixing the problem.
Unfortunately, that includes Spamhaus.
It's a bit sad to see how many companies will blindly support such entities because they've "heard" that they somehow help fight spam. As someone who's had issues with them because of their badly configured hosts and shady practices (e.g. using domains previously used by mail providers as "spam honeypots", meaning anyone who emails someone with an old address can be banned [all content mailed there is considered spam, regardless of what it actually is]), I am disappointed (yes, looking at you cloudflare).
Some of my sites have had short periods of slow response times for the past few days but I assumed it's the crappy host their on. One of my clients on CF hasn't had any issues.
I assume it was related to this attack.