ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Pi-hole server involved in a 'DNS Amplification' DDOS Attack

    IT Discussion
    pi-hole pihole ddos dns amplification
    9
    69
    7.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Curtis @bnrstnr
      last edited by

      https://freek.ws/2017/03/18/blocking-dns-amplification-attacks-using-iptables/

      DustinB3403D 1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403 @Curtis
        last edited by

        @Curtis said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

        https://freek.ws/2017/03/18/blocking-dns-amplification-attacks-using-iptables/

        That filtering will only work for LAN only, at least as documented and would be troublesome to complete for this use case as @bnrstnr is hosting a public DNS for friends and family. All of whom likely are in different public networks.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @CloudKnight
          last edited by

          @StuartJordan said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

          Have you looked in /var/logs? might be worth looking to see how they have managed to get in. otherwise you could setup another PI-Hole and the same thing could happen. Did you use a secure passwords for SSH and the login page? no dictionary passwords?

          DNS Amplification does not require a breach, nor suggest one. It's just something that can happen to public DNS.

          1 Reply Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller @DustinB3403
            last edited by

            @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

            @Curtis said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

            https://freek.ws/2017/03/18/blocking-dns-amplification-attacks-using-iptables/

            That filtering will only work for LAN only, at least as documented and would be troublesome to complete for this use case as @bnrstnr is hosting a public DNS for friends and family. All of whom likely are in different public networks.

            Yup, very little that can be done.

            1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403
              last edited by

              Dumb question for @bnrstnr why not setup PiHole individually for each of your friends and families networks rather than dealing with a public DNS for everyone.

              Is there a reason to have this setup like this besides it being cool?

              scottalanmillerS B 2 Replies Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @DustinB3403
                last edited by

                @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                Dumb question for @bnrstnr why not setup PiHole individually for each of your friends and families networks rather than dealing with a public DNS for everyone.

                Is there a reason to have this setup like this besides it being cool?

                Uses a fraction of the resources, can work for people who are mobile, etc.

                DustinB3403D 1 Reply Last reply Reply Quote 1
                • DustinB3403D
                  DustinB3403 @scottalanmiller
                  last edited by DustinB3403

                  @scottalanmiller said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                  @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                  Dumb question for @bnrstnr why not setup PiHole individually for each of your friends and families networks rather than dealing with a public DNS for everyone.

                  Is there a reason to have this setup like this besides it being cool?

                  Uses a fraction of the resources, can work for people who are mobile, etc.

                  That's true but he wouldn't need to deal with issues like the one he's currently dealing with.

                  Edit this also assumes that at least on their mobile computers (laptops) that the DNS is statically configured.

                  Seems like a bad approach.

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @DustinB3403
                    last edited by

                    @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                    @scottalanmiller said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                    @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                    Dumb question for @bnrstnr why not setup PiHole individually for each of your friends and families networks rather than dealing with a public DNS for everyone.

                    Is there a reason to have this setup like this besides it being cool?

                    Uses a fraction of the resources, can work for people who are mobile, etc.

                    That's true but he wouldn't need to deal with issues like the one he's currently dealing with.

                    Edit this also assumes that at least on their mobile computers (laptops) that the DNS is statically configured.

                    Seems like a bad approach.

                    It's how Cisco and others handle it.

                    This issue doesn't come up often. Never seen it previously.

                    1 Reply Last reply Reply Quote 0
                    • B
                      bnrstnr @DustinB3403
                      last edited by

                      @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                      Dumb question for @bnrstnr why not setup PiHole individually for each of your friends and families networks rather than dealing with a public DNS for everyone.

                      How would I set it up individually for everybody? None of my friends or family has a raspberry pi, server, or anything that could run it. I use a $2.50 instance on vultr.

                      DashrenderD 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @bnrstnr
                        last edited by

                        @bnrstnr said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                        @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                        Dumb question for @bnrstnr why not setup PiHole individually for each of your friends and families networks rather than dealing with a public DNS for everyone.

                        How would I set it up individually for everybody? None of my friends or family has a raspberry pi, server, or anything that could run it. I use a $2.50 instance on vultr.

                        They'd need one of those thing each for themselves to run it individually.

                        Scott's post points out why that's likely a less than desirable solution.

                        DustinB3403D 1 Reply Last reply Reply Quote 1
                        • DustinB3403D
                          DustinB3403 @Dashrender
                          last edited by

                          @bnrstnr Dash beat me to the answer.

                          But yeah, you'd setup a Pi in each person's network and then configure their local DNS to use the PiHole.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender
                            last edited by

                            The occasional complaint is nothing something I would worry about - especially when you're doing nothing wrong - I wouldn't change anything from what you have today. it's way to flexible and low cost to worry about changing.,

                            B 1 Reply Last reply Reply Quote 2
                            • B
                              bnrstnr @Dashrender
                              last edited by

                              @Dashrender said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                              The occasional complaint is nothing something I would worry about - especially when you're doing nothing wrong - I wouldn't change anything from what you have today. it's way to flexible and low cost to worry about changing.,

                              That's the way I'm leaning, too. I might try to do some geo-blocking, but I doubt I'll ever get to it. Especially since nobody here has seen this before on their piholes.

                              DustinB3403D 1 Reply Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403 @bnrstnr
                                last edited by

                                @bnrstnr said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                @Dashrender said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                The occasional complaint is nothing something I would worry about - especially when you're doing nothing wrong - I wouldn't change anything from what you have today.  it's way to flexible and low cost to worry about changing.,
                                

                                That's the way I'm leaning, too. I might try to do some geo-blocking, but I doubt I'll ever get to it. Especially since nobody here has seen this before on their piholes.

                                I don't think anyone else here is using PiHole as a public DNS. . .

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @DustinB3403
                                  last edited by

                                  @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                  @bnrstnr said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                  @Dashrender said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                  The occasional complaint is nothing something I would worry about - especially when you're doing nothing wrong - I wouldn't change anything from what you have today.  it's way to flexible and low cost to worry about changing.,
                                  

                                  That's the way I'm leaning, too. I might try to do some geo-blocking, but I doubt I'll ever get to it. Especially since nobody here has seen this before on their piholes.

                                  I don't think anyone else here is using PiHole as a public DNS. . .

                                  I am.

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @DustinB3403
                                    last edited by

                                    @DustinB3403 said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                    @bnrstnr Dash beat me to the answer.

                                    But yeah, you'd setup a Pi in each person's network and then configure their local DNS to use the PiHole.

                                    That's non-trivial for home users or really small SMBs. You need somewhere to run that and most people don't have servers.

                                    1 Reply Last reply Reply Quote 0
                                    • gjacobseG
                                      gjacobse
                                      last edited by

                                      Had the same thing happen to my Vultr Pi-Hole.. I deleted the server for the time being.. and may not rebuild.

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @gjacobse
                                        last edited by

                                        @gjacobse said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                        Had the same thing happen to my Vultr Pi-Hole.. I deleted the server for the time being.. and may not rebuild.

                                        I thought you had a WARNING that it COULD happen, not that it DID happen.

                                        gjacobseG 1 Reply Last reply Reply Quote 0
                                        • gjacobseG
                                          gjacobse @scottalanmiller
                                          last edited by

                                          @scottalanmiller said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                          @gjacobse said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                          Had the same thing happen to my Vultr Pi-Hole.. I deleted the server for the time being.. and may not rebuild.

                                          I thought you had a WARNING that it COULD happen, not that it DID happen.

                                          Correct.. the notice came in over the weekend.

                                          scottalanmillerS dbeatoD 2 Replies Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @gjacobse
                                            last edited by scottalanmiller

                                            @gjacobse said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                            @scottalanmiller said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                            @gjacobse said in Pi-hole server involved in a 'DNS Amplification' DDOS Attack:

                                            Had the same thing happen to my Vultr Pi-Hole.. I deleted the server for the time being.. and may not rebuild.

                                            I thought you had a WARNING that it COULD happen, not that it DID happen.

                                            Correct.. the notice came in over the weekend.

                                            Right, totally different. One is being told you have an open port, which is essentially guaranteed to happen as Vultr does that every few days. The other is very unlikely, an actual attack.

                                            Everyone on Vultr gets the one. When we said that no one else has had this happen, you didn't have it happen either.

                                            gjacobseG 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 3 / 4
                                            • First post
                                              Last post