|
|
|
|
|
by majke
3853 days ago
|
|
Nope. The open recursive DNS servers, are real DNS servers, with caching and backoff logic. If, say, there are 94k [1] open DNS resolvers in the wild, each will ask you one DNS question for example.com, cache the answer and that's it. The big volume for the "fixed domain" queries indicates proper BCP-38 spoofing. [1] http://public-dns.tk/ |
|
Further, recent research has shown the number of open DNS resolvers to be in the range of 15-30 million[1].
Since the article describes a single domain name was used in the attack however, that's not what happened here.
[1] http://icir.net/mallman/papers/dns-probe-meth-imc13.pdf