- http://isc.sans.org/diary.html?storyid=2184
Last Updated: 2007-02-06 23:40:41 UTC ~ "…News of the attacks against the DNS root servers. We are aware of the attacks, and have been waiting to wade through the FUD before publishing anything more concrete. I am posting this now just to let our readers know that we are aware of the story and that we are trying to get more information about it…
The main story is featured here:
> http://tinyurl.com/25kw49
Here are some graphs showing the traffic rates to the root servers here:
> http://tinyurl.com/2yr8fj …"
- http://news.yahoo.com/s/ap/20070206/ap_on_…ernet_attacks_4
2/6/2007 ~ "Hackers briefly overwhelmed at least three of the 13 computers that help manage global computer traffic Tuesday in one of the most significant attacks against the Internet since 2002. Experts said the unusually powerful attacks lasted as long as 12 hours but passed largely unnoticed by most computer users, a testament to the resiliency of the Internet. Behind the scenes, computer scientists worldwide raced to cope with enormous volumes of data that threatened to saturate some of the Internet's most vital pipelines…. Other experts said the hackers appeared to disguise their origin, but vast amounts of rogue data in the attacks were traced to South Korea. The attacks appeared to target UltraDNS, the company that operates servers managing traffic for Web sites ending in "org" and some other suffixes, experts said. Officials with NeuStar Inc., which owns UltraDNS, confirmed only that it had observed an unusual increase in traffic. Among the targeted "root" servers that manage global Internet traffic were ones operated by the Defense Department and the Internet's primary oversight body… Crain said Tuesday's attack was less serious than attacks against the same 13 "root" servers in October 2002 because technology innovations in recent years have increasingly distributed their workloads to other computers around the globe."
- http://www.informationweek.com/shared/prin…cleID=197003903
Feb. 6, 2007 ~ "…The main attack hit the roots at 5:30 a.m. ET on Tuesday, and reached its maximum sustained traffic at 7 a.m. It started to subside around 10:30 that morning and was still going on - though rather weakly - at 7 p.m. Tuesday. Denial of service attacks – sometimes called DoS - are designed to pound each computer with countless questions that flood its ability to respond; effectively taking the machine down…"
- http://www.theregister.com/2007/02/07/root_server_attack/
7 February 2007 ~ "…The DOD's G server was among those sustaining the most damage, according to an analysis of the machine's unanswered queries. The L server, maintained by ICANN, and the WIDE Project's M server, located in multiple locations, were also hit in attacks that started a little after midnight GMT on Tuesday. There were reports that F and I servers also faced increased traffic, but those attacks appeared to be short-lived. They appeared to affect certain top-level-domains, including .org… There were few reports of widespread outages, which comes as little surprise since the group of 13 root servers, which is then broken up into dozens more smaller, geographically dispersed servers, were designed so that two-thirds can fail with no noticeable interruption. Whois and other services provided by ICANN were down for a time, according to a post* on a discussion group. Despite the inefficacy of the attack, federal authorities, especially those in the military, never take kindly to attacks on their infrastructure…"
- http://www.us-cert.gov/current/#dnsanom
February 6, 2007 ~ "…It is likely that the traffic is Distributed Denial of Service (DDOS) related. At approximately 0001 GMT on 6 Feb 2007, several root-level DNS servers began receiving a large volume of malformed DNS queries. This initial attack appears to have been a warm-up for a much larger attack that began at 1000 GMT. DNS servers G (U.S. DOD Network Information Center), L (Internet Corporation for Assigned Names and Numbers), and M (WIDE Project) appear to have been the most severely impacted although none were ever unreachable. The servers were operational and reachable even with the high volume of traffic. US-CERT has been in contact with the various groups affected to ensure that appropriate actions are being taken…"
- http://preview.tinyurl.com/yr53aa
March 12, 2007 ~ "…DNS servers came through February's attack relatively unscathed because of the Anycast load-balancing technology put in place after the last major attack in 2002. The attack targeted six of the 13 root servers. The two servers that fared the worst during the attack did not yet have the technology installed. The root server operators also played a significant role in preventing the attack from having a noticeable effect on Internet users worldwide by staying in constant communication. The operators noticed that all the attack packets were larger than 512-bytes and consequently blocked packets that met that criterion. That step alone managed to stop the attack in its tracks…"