Open Recursive Resolvers pose a significant threat to the global network infrastructure. They are utilized in DNS Amplification attacks and pose a similar threat as those from Smurf attacks commonly seen in the late 1990's.
If you are a member of the general public:
We have collected a list of 27 million resolvers that respond to queries in some fashion. 25 million of these pose a significant threat (as of 24-MAR-2013).
If you operate a DNS server, please check the settings. Authoritative servers should not offer recursion, but can still be used in an attack. Consider Configuring Rate Limiting in your software. Recursive servers should be restricted to your enterprise or customer IP ranges to prevent abuse.
Directions on securing nameservers can be found at Team Cymru
We hope to present the data at a future conference, and share it with the broader security community. DNS servers are used as part of DDoS reflection or amplification attacks.
DNS DDoS in the NewsMeasurement-Factory[external-link]: List of Open Resolvers by ASN
If you are in the security community:
Please contact dns-scan /at/ puck.nether.net or if you know the host owner, engage him for access to raw data.
What can I do?
Configure BCP-38 on all CPE and Datacenter equipment edges that have fixed IP ranges. This could be as simple as setting ip verify unicast source reachable-via rx on a router interface. Any staticly routed customer should receive this setting by default.
Configure your DNS servers with DNS RRL. Knot DNS and NLNetLabs NSD include this as a standard option now. BIND requires a patch. For more information check the Rate Limits in DNS Website

