DDoS attacks against Zerigo DNS services
zerigostatus.net
zerigostatus.net
That said, it is UNFORGIVABLE (imo) that Zerigo failed to send ANY type of notification to its DNS customers... they have apparently been having ddos trouble for about 24 hours.
afaik they do not offer any type of text or email alerts when they are experiencing trouble (such as the SMS messages I get from Heroku).
So, while I like their tools, and the ddos hasn't affected our website that have secondary DNS, we will "walk" to another provider that cares enough about their customers to offer proactive alerts.
a.ns.zerigo.net 64.27.57.11, announced by WeHostWebSites.com
b.ns.zerigo.net 174.37.229.229, SoftLayer
c.ns.zerigo.net 109.74.192.232, Linode
d.ns.zerigo.net 174.36.24.250, Softlayer
e.ns.zerigo.net 72.26.219.150, Voxel.net (Internap)
f.ns.zerigo.net 223.27.170.242, Voxel.net (Internap)
Almost three years ago, DnsMadeEasy (which as far as I know dwarf DNSimple and Zerigo) had an outage after a massive attack.
"Zerigo has procedured DDOS mitigation services from Verisign and is in the process of integrating them into our network to prevent such attacks from compromising our DNS services in the future."
A target (like a High Yield Investment Program, a pro-choice website, online casino, etc) will be using ProviderA and the attackers will hit their DNS in an attempt to take the site down. The target will want to get back online (or get terminated by ProviderA) and jump over to ProviderB. The attackers see the change, and take down the new provider. Rinse and repeat forever.
On the backend most of the large DNS providers share a common blacklist of sites they have terminated so you can't just provider hop and drag the attack around with you. I don't think DNSimple or Zergio participates, though.