Hacker News new | ask | show | jobs
by gabriel-samfia 5074 days ago
We've seen the same kind of attack. We ended up limiting our DNS resolvers only to our own prefixes. It's a simple ACL in bind that allows recursion (domains your DNS server is not authoritative for), only to our subnets.