DNSimple DDOS Attack
dnsimplestatus.com
dnsimplestatus.com
Nonetheless, we just spun up a Route53 zone, exported our zone from DNSimple, imported to Route53, and hand-migrated our ALIAS records to static A records in the new zone.
Not perfect or permanent, but we've gotten around the outage. Also, I just learned that pointhq has (seemingly-undocumented) support for ALIAS records in the same style as DNSimple, so this could be another avenue to explore.
They brag about "99.9999% uptime history" at http://www.dnsmadeeasy.com/technology/.
Though they doesn't seem as innovative and nice as DNSimple. Really hope things work out for DNSimple (really like the idea of their beta feature GitHub sync).
(I wrap Amazon's route53 with DNS entries read from github/gitbucket/similar.)
An interesting/custom choice to use JSON, and real github integration rather than using hooks as I did.
However, making your DNS servers to be responsible for serving their own DNS is a bit of an extra complexity and risk that no customer will ever care about..
http://aws.amazon.com/blogs/aws/route-53-update-private-dns-...
"You can create generic "white label" name servers such as ns1.example.com and ns2.example.com, use them in your delegation set, and point them to your actual Route 53 name servers."
Does that answer the question? I'm a little hazy on what you're actually asking.
Their interface is pretty bad, but the backend is hardy.
If I do a traceroute to the 5 DNSMadeEasy name server records (they actually run many more hosts) I go via 3 different networks - GTT, NTT, and Tata.
FWIW, the IP I have cached is 50.31.213.210.
Fascinating traffic floods from various locations, but the attack is not continuous.
As far as I understand, ipviking simply hosts honeypots around the world and uses those to graph "attacks" against IP blocks, etc.
I would very much like someone to correct me if this assumption is incorrect, because it'd be neat to actually watch targeted DDoS attacks, but I don't think that's what ipviking is offering.
FYI - Instead of an Alias record on DNSimple, CloudFlare will allow a CNAME record for the root domain using "CNAME flattening".
You can now set CloudFlare's DNS service to "bypass Cloudfare" on all records by clicking the icon so you don't get any of their magic (unless you want it).
Then add CloudFlare's 2 nameserves to your domain as your first 2 name servers. No need to remove dnsimple's name servers.
Now you have 2 DNS providers in case one fails, just make sure the records are the same across them both!
Any ideas?
I wonder how many of the affected companies do have redundant appservers and load balancers, but missed this piece of the puzzle...
Small wonder that a proprietary syntactical sugar leaves you at the mercy of select vendors?
As for volumetric attacks: your point is correct, but is irrelevant if you're using multiple vendors, and a specific, single vendor is the target, like it appears here. Your other authoritative servers would be unaffected.
1 http://support.dnsimple.com/articles/alias-record/, or http://webcache.googleusercontent.com/search?q=cache:ST1BABj...
anyway, you're not wrong, the best approach to mitigate this kind of thing is to leverage multiple dns networks. but doing so is not easy unless the application is still using dns like it was in 1995, and that is increasingly rarely the case.
(Or is there more to ALIAS than that, which wasn't on the page in GP? Happy to be corrected if so)
I agree though that it is a pretty simple service to run for a small domain.
But agreed, if you are the target, you're going to be hosed either way.
You could pay GoDaddy, Amazon Route 53, and DNSSimple to all host your records, for example... Management would be slower and manual, but people without resources for "managing your own DNS" won't be changing records that frequently anyways.
The odds of all three going down at once should help your uptime, yes?
I'm hoping it will get queued by the sending server, and make it's way back when DNSimple is up and running. Is that correct?
What can you do to prevent this in future? Can you run multiple DNS providers simultaneously? So, ns1/ns2 go to DNSimple, and ns3/ns4 go to another provider?
No.
> Or is that only to keep things in sync automatically?
Yes.
We manually exported our DNS configuration from DNSimple as a single file and imported it to DNSMadeEasy. Pretty easy transition, although we have to make future changes in two places.
I set 2 nameservers on the old host and 2 on the new, and am keeping that configuration for automatic failover in the future. The DNS propagated fairly quickly and our site was up and running for many users within an hour. Glad that's over with.
We've successfully switched our domains over to nsone.net.
Set up a new account on another host that does ALIAS records (I used pointDNS)
Create your new record without much in it
Change your nameservers on your domain now - they'll take time to propagate
Fill in the records on your domain. If you can't remember them, print out most of your existing records with
dig yourdomain.com ANY
Add the rest of the records to pointDNS
Wait for the new Nameservers to propagate (0-24 hours - it took 15-30 min for us on a small-medium traffic domain today during sales crunch)
If you really really want to do it anyway, most caches use either the TTL on your SOA record, or the final field in the SOA record as the negative cache TTL; so lower both of those values to something like 60 seconds.
https://twitter.com/dnsimplestatus/status/539551209452232705
Unlike Dyn or CloudFlare:
"Some DNS hosts provide a way to get CNAME-like functionality at the zone apex using a custom record type. " .. and then on to suggest DNSimple as their first suggestion.
Heroku prefers you didn't use A RECORDS at all because the IP addresses in their underlying architecture might change. [1]
Google, Facebook, etc, all use this approach.
Many customers were able to resolve the domain in the minutes immediately following the switch, and the rest seem to be trickling in.
EDIT: right, must have been able to log in during a brief period where dnsimple was not down.
We went by this:
(ObRandom: I run a service that wraps route53 with git integration, at https://dns-api.com/ )
https://medium.com/@brianarmstrong/youre-probably-doing-dns-...
I always wonder, why is it that someone wants to attack a small company like DNSimple ? Is it that they were blackmailed and did not surrender to the criminals? If so, why would anyone be interested in blackmailing such a small company?
dnsimple domain record list example.com > example.txt
OR
dnsimple domain record list example.com --json > example.json
Hence, I'm going to try CloudFlare (assuming they take over DNS hosting, I need to check) and Google Cloud DNS, because then all parts of my site (from DNS to CSS hosting) will be with providers with bigger pipes than attackers can create. Hopefully that will prevent this kind of attack from taking my site down.
The reason for this is that resolvers will generally try at least three different name servers before giving up, so if you have three or more from a single provider that may not help.
There is also a big caveat to consider: once you use two more providers, whenever you need to make rapid DNS changes for your own availability reasons you will need to wait for the slowest-to-update provider.
my experience shows, that at least 3 servers with 3 different providers is good enough. and "providers" I mean different company, city, datacenter, transit provider...
trusting single entity with anything (even if they say that they have many servers blabla... geologically blabla...)... well, you have situation like this right now :)
* Get accounts with AWS (Route 53), dnsmadeeasy, and cloudflare.
* Monitor resolution at all of their name servers
* Either proactively spread your authoritative nameservers across providers, or update your root NS records based on your monitoring.
"DDoS attacks...will generally fall into one of three broad categories:
Volumetric Attacks: Attempt to consume the bandwidth either within the target network/service, or between the target network/service and the rest of the Internet. These attacks are simply about causing congestion."
Deleted comment
The best thing you can do right now is to reach out and offer your help, privately. Even from a selfish perspective, you'll learn a lot about the attack that is taking them down now which will help you out when the targeted customer inevitably signs up for your service.
EDIT: The parent comment was spam from Kris Beevers at NSone.
you're not wrong: in this industry you never kick your competitors when they're down, everyone is subject to the same constraints, attacks, and complications. that wasn't my intention and i said so in the post.