TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Zerigo DNS services down for 6+ hours due to massive DDoS

39 pointsby _phredalmost 13 years ago

18 comments

cbsmithalmost 13 years ago
I can totally buy DDoS flooding network capacity, but I'm befuddled these days by statements saying the servers are "under load", which typically means "out of CPU". It's kind of hard for me to imagine even an i5 not being able to saturate a gigE line with DNS lookups (yes, it is a lot of packets, but it can be done) unless DNSSec is going on. Even 10gigE, <i>if</i> you can amortize interrupts, seems like it'd not be hard to saturate with today's hardware.<p>What am I missing here?
评论 #4307985 未加载
aedenalmost 13 years ago
I run DNSimple (<a href="https://dnsimple.com" rel="nofollow">https://dnsimple.com</a>) and we have a full REST API and support domain registrations, transfers and SSL certificates as well. Plus we have an ALIAS record type that's very useful for pointing your apex to services where they only provide a hostname.<p>I'll be happy to answer any questions you have regarding our service either here or through our support channels.
评论 #4280618 未加载
评论 #4280564 未加载
评论 #4280991 未加载
评论 #4282464 未加载
评论 #4280753 未加载
评论 #4280612 未加载
评论 #4280867 未加载
评论 #4280594 未加载
评论 #4281341 未加载
评论 #4280639 未加载
评论 #4280599 未加载
评论 #4280542 未加载
_phredalmost 13 years ago
Going on 8 hours of Zerigo's downtime I've had to move all of our Zerigo DNS to DNSMadeEasy. It's a shame, because I really, really like Zerigo, especially their API.<p>Shit happens, but 99.9% (8 hours a year of downtime) is completely unacceptable for a DNS provider.
sstarralmost 13 years ago
Add these to your hosts file to access your account:<p>64.27.57.25 manage.zerigo.com<p>64.27.57.8 dns.zerigo.com<p>Source: <a href="https://twitter.com/coldclimate/status/227369346891132928" rel="nofollow">https://twitter.com/coldclimate/status/227369346891132928</a>
评论 #4280510 未加载
latchalmost 13 years ago
Seems like if you are serious about mitigating this type of issue (as a consumer), you really should be specifying name servers from different providers. Your primary DNS server can be from dnsimple/zerigo/dnsmadeeasy and your secondary can be route53, or you could run your own.<p>The only problem seems to be keeping them in sync. Seems like you'd have to poll the primary (using whatever API it exposes) to update the secondary.<p>Mostly thinking out loud, surely someone more experienced could provide better guidance?
评论 #4280710 未加载
jbarhamalmost 13 years ago
I run a DNS hosting service (SlickDNS, www.slickdns.com) and have seen a spike in signups today as a direct result of the Zerigo DDOS attack.<p>I can't claim that SlickDNS is invulnerable to DDOS attack, but FWIW it does run tinydns name servers which have good performance and excellent security. So if you're impacted by the Zerigo outage, feel free to check out SlickDNS. There's a 30-day free trial with all plans and record updates are pushed through to all the name servers in under 5 seconds.
评论 #4280543 未加载
评论 #4280487 未加载
_phredalmost 13 years ago
Apparently no ETA for restore as of 2 hours ago: <a href="https://twitter.com/zerigo/status/227322909230768128" rel="nofollow">https://twitter.com/zerigo/status/227322909230768128</a>
gaiaalmost 13 years ago
Best thing Zerigo could do for their customers at this point is export all zone information and email it to them or make available for DL. I have a feeling this is going to be a long outage. In the meanwhile, here is a great list of free DNS providers (dont get caught without a secondary DNS provider): <a href="http://www.lowendtalk.com/wiki/free-dns-providers" rel="nofollow">http://www.lowendtalk.com/wiki/free-dns-providers</a>
metalruleralmost 13 years ago
I've been seeing a lot of reflector attacks in the past couple of weeks, where the attacker sends a relatively small query for a valid domain that will return a large reply. The trick is that they spoof the source IP, so the DNS reply goes to the victim.<p>I ended up hacking something together to firewall any IPs which sent more than 1000 requests in a short period of time.
评论 #4327948 未加载
评论 #4281619 未加载
AdamGibbinsalmost 13 years ago
And this is why I use Route 53, I'm a lot more confident in Amazon's abilities to mitigate DDoS attacks.<p>Which really sucks, DDoS are really hard to combat and Zerigo are an awesome company.
manverualmost 13 years ago
Well, that explains why my wife woke me up complaining about half the internet not working. Our ISP is 3 (drei.at) and she was using their DNS, guess there are issues all over Europe.
sligalmost 13 years ago
What are the main advantages of paying for DNS hosting like Zerigo or SlickDNS instead of using the one provided for free with web host companies (E.g. Linode's DNS Manager)?
评论 #4280674 未加载
评论 #4280546 未加载
sleighboyalmost 13 years ago
US-Based customer here. Our DNS just started working again.
Uchikomaalmost 13 years ago
Running with DNSMadeEasy, is there a way to integrate it with Route 53 through AXFR to have two providers?
评论 #4281055 未加载
评论 #4281056 未加载
piggityalmost 13 years ago
Days later and what do we have from them? One solitary email and a few half-assed status page updates.
St-Clockalmost 13 years ago
This took down services like Fogbugz on demand.
评论 #4281031 未加载
silverlightalmost 13 years ago
Looks like this took Trello down, too...
评论 #4281050 未加载
PonyGumboalmost 13 years ago
Comodo's DNS.com appears to be down too.