1. ksanislo

    OP ksanislo GBAtemp Fan
    Member

    Joined:
    Feb 23, 2016
    Messages:
    386
    Country:
    United States
    I'm performing some maintenance on the DNS servers. In the interest of safety I'll be blocking all DNS queries until finished from one server at a time, so they can't accidentally leak unfiltered responses. They are expected to be down only a few minutes each.

    update: Maintenance has been concluded. The backend has been changed from bind9 to powerdns, since pdns provides a mechanism that will help prevent being used as a DDoS relay, and I'd rather prefer not dealing with that sort of thing.
     
    Last edited by ksanislo, Jan 3, 2017
    hippy dave and zeldaism like this.
  2. Phemeto

    Phemeto GBAtemp Regular
    Member

    Joined:
    Jan 21, 2016
    Messages:
    129
    Country:
    United States
    Thank you keep up with this, since the recent attacks against the other
     
  3. ksanislo

    OP ksanislo GBAtemp Fan
    Member

    Joined:
    Feb 23, 2016
    Messages:
    386
    Country:
    United States
    These should remain up for the foreseeable future. I'd actually attempted to warn the operator of the DNS-U setup about his vulnerability of becoming a DDoS amplifier, but he apparently wasn't interested in fixing it.
     
  4. Ninja_Carver

    Ninja_Carver GBAtemp Fan
    Member

    Joined:
    Dec 27, 2012
    Messages:
    364
    Country:
    United States
    that's kind of a big assumption. i did try several iptables entries to defeat the attack but none worked.
     
  5. ksanislo

    OP ksanislo GBAtemp Fan
    Member

    Joined:
    Feb 23, 2016
    Messages:
    386
    Country:
    United States
    You can't block the "source" addresses of a UDP based DNS amplification attack because that's a forged address of the DDoS target. You must utilize something such as PowerDNS's any-to-tcp option which returns a 'truncated' result to any UDP ANY query, requiring the client to switch to TCP which can't be forged in order to perform a query for ANY type records.
     
  6. Ninja_Carver

    Ninja_Carver GBAtemp Fan
    Member

    Joined:
    Dec 27, 2012
    Messages:
    364
    Country:
    United States
    i'm familiar with how an amplification attack works and didn't say i was trying to block the source addresses.. christ you make a lot of generalizations. anyways, its not really worth the effort of rebuilding the server with powerdns. cheers.
     
  7. ksanislo

    OP ksanislo GBAtemp Fan
    Member

    Joined:
    Feb 23, 2016
    Messages:
    386
    Country:
    United States
    I apologize if I came off as rude, and you're right that I made some possibly incorrect assumptions as to how your system was configured. Thank you for your support of the community with your service. If you do decide you wish to continue DNS-U with pdns later on, I'm sure people would be grateful for more options.
     
  8. DarkFlare69

    DarkFlare69 GBAtemp Guru
    Member

    Joined:
    Dec 8, 2014
    Messages:
    5,144
    Country:
    United States
    thanks for this, hopefully no one abuses it like they did with DNS-U.
     
  9. shinobita

    shinobita Newbie
    Newcomer

    Joined:
    Oct 14, 2015
    Messages:
    9
    Country:
    Italy
  10. adittya

    adittya Newbie
    Newcomer

    Joined:
    Apr 9, 2017
    Messages:
    7
    Country:
    Indonesia
    is this dns still work? i cant connect to internet today
     
  11. Deleted User

    Deleted User Newbie

    I'm typing this from a Wii U so, yeah. It still works.
     
    Deleted User likes this.
  12. adittya

    adittya Newbie
    Newcomer

    Joined:
    Apr 9, 2017
    Messages:
    7
    Country:
    Indonesia
    well the problem is my wii u then. thanks for the info

    can somebody help me with the problem?
     
    Last edited by adittya, Apr 27, 2017
  13. Deleted User

    Deleted User Newbie

    Yeah, what problem are you having?
     
  14. adittya

    adittya Newbie
    Newcomer

    Joined:
    Apr 9, 2017
    Messages:
    7
    Country:
    Indonesia
    i cant connect to internet with the dns. but with auto dns i can connect without problem. without internet i cant open hbl
    i already reset router, try another router, try with another connection, reset wii u couple times the result are the same
     
    Last edited by adittya, Apr 27, 2017
  15. ksanislo

    OP ksanislo GBAtemp Fan
    Member

    Joined:
    Feb 23, 2016
    Messages:
    386
    Country:
    United States
    Doing some maintenance on these DNS servers today. I'll be blocking them off from public access while working, to make sure I don't accidentally leak valid results out and let someone's console update unexpectedly. As long as you have BOTH of mine configured, you shouldn't see an impact. Anybody who still has one of the dead, alternate services (tubehax, dns-u) on their system will probably lose internet briefly.
     
  16. ksanislo

    OP ksanislo GBAtemp Fan
    Member

    Joined:
    Feb 23, 2016
    Messages:
    386
    Country:
    United States
    Maintenance has been concluded. Services are back up and running as expected on both systems.
     
    Deleted User likes this.
  17. Xerkies

    Xerkies Member
    Newcomer

    Joined:
    Dec 14, 2016
    Messages:
    29
    Country:
    United States
    Now my internet doesn't work. It did work before but now it doesn't
     
  18. AmandaRose

    AmandaRose Do what I do. Hold tight and pretend it’s a plan
    Member

    Joined:
    Aug 19, 2015
    Messages:
    8,177
    Country:
    United Kingdom
    Well something is wrong at your end as I use those blockers and can access the Internet with zero problems.
     
  19. Abbas_Zaini

    Abbas_Zaini Newbie
    Newcomer

    Joined:
    Feb 17, 2017
    Messages:
    4
    Country:
    Are they down again? Because I had an unexpected update download that I somehow noticed and powered off to prevent.
     
  20. SomeGamer

    SomeGamer GBAtemp Guru
    Member

    Joined:
    Dec 19, 2014
    Messages:
    6,820
    Country:
    Hungary
    It they're down, your Wii U can't do any DNS resolutions -> no internet at all.
     
    Abbas_Zaini likes this.
Draft saved Draft deleted
Loading...

Hide similar threads Similar threads with keywords - Blocking, TitleDB, Servers