Published 3 days ago
3 mins read
Post-Mortem: Anatomy of a DNS Amplification Attack on one of our public server.
You're settling in with a fresh cup of coffee, and suddenly your NOC monitoring screen turns as bright red as an emergency flare. A single server whose public IP address was unfortunately a little too well-known across the internet just became the target of a massive DNS Amplification DDoS Attack.
As an Internet Service Provider (ISP), we see our fair share of weird traffic. But watching a single host get flooded with a 10 Gigabit wall of uninvited DNS answers is a classic scenario that goes from "interesting textbook theory" to "all-hands-on-deck emergency" in about four seconds flat.
Continue reading