The Wayback Machine - https://web.archive.org/web/20130327233828/http://openresolverproject.org/

Open DNS Resolver Project

Open Recursive Resolvers pose a significant threat to the global network infrastructure. They are utilized in DNS Amplification attacks and pose a similar threat as those from Smurf attacks commonly seen in the late 1990's.

WHAT CAN I DO?

Search my IP space (eg: 192.0.2.0/24 - searches "larger" than /24 will be rejected):

hilbert curve heatmap of 20130324 data


If you are a member of the general public:

We have collected a list of 27 million resolvers that respond to queries in some fashion. 25 million of these pose a significant threat (as of 24-MAR-2013).

If you operate a DNS server, please check the settings. Authoritative servers should not offer recursion, but can still be used in an attack. Consider Configuring Rate Limiting in your software. Recursive servers should be restricted to your enterprise or customer IP ranges to prevent abuse.

Directions on securing nameservers can be found at Team Cymru

We hope to present the data at a future conference, and share it with the broader security community. DNS servers are used as part of DDoS reflection or amplification attacks.

DNS DDoS in the News
  • 20-MAR-2013 75Gb/s DDoS against Cloudflare
  • 23-FEB-2013 Some DNS Servers being closed

    Measurement-Factory[external-link]: List of Open Resolvers by ASN

  • If you are in the security community:

    Please contact dns-scan /at/ puck.nether.net or if you know the host owner, engage him for access to raw data.

    What can I do?

    Configure BCP-38 on all CPE and Datacenter equipment edges that have fixed IP ranges. This could be as simple as setting ip verify unicast source reachable-via rx on a router interface. Any staticly routed customer should receive this setting by default.

    Configure your DNS servers with DNS RRL. Knot DNS and NLNetLabs NSD include this as a standard option now. BIND requires a patch. For more information check the Rate Limits in DNS Website