TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Zerigo DNS services down for 6+ hours due to massive DDoS

39 点作者 _phred将近 13 年前

18 条评论

cbsmith将近 13 年前
I can totally buy DDoS flooding network capacity, but I'm befuddled these days by statements saying the servers are "under load", which typically means "out of CPU". It's kind of hard for me to imagine even an i5 not being able to saturate a gigE line with DNS lookups (yes, it is a lot of packets, but it can be done) unless DNSSec is going on. Even 10gigE, <i>if</i> you can amortize interrupts, seems like it'd not be hard to saturate with today's hardware.<p>What am I missing here?
评论 #4307985 未加载
aeden将近 13 年前
I run DNSimple (<a href="https://dnsimple.com" rel="nofollow">https://dnsimple.com</a>) and we have a full REST API and support domain registrations, transfers and SSL certificates as well. Plus we have an ALIAS record type that's very useful for pointing your apex to services where they only provide a hostname.<p>I'll be happy to answer any questions you have regarding our service either here or through our support channels.
评论 #4280618 未加载
评论 #4280564 未加载
评论 #4280991 未加载
评论 #4282464 未加载
评论 #4280753 未加载
评论 #4280612 未加载
评论 #4280867 未加载
评论 #4280594 未加载
评论 #4281341 未加载
评论 #4280639 未加载
评论 #4280599 未加载
评论 #4280542 未加载
_phred将近 13 年前
Going on 8 hours of Zerigo's downtime I've had to move all of our Zerigo DNS to DNSMadeEasy. It's a shame, because I really, really like Zerigo, especially their API.<p>Shit happens, but 99.9% (8 hours a year of downtime) is completely unacceptable for a DNS provider.
sstarr将近 13 年前
Add these to your hosts file to access your account:<p>64.27.57.25 manage.zerigo.com<p>64.27.57.8 dns.zerigo.com<p>Source: <a href="https://twitter.com/coldclimate/status/227369346891132928" rel="nofollow">https://twitter.com/coldclimate/status/227369346891132928</a>
评论 #4280510 未加载
latch将近 13 年前
Seems like if you are serious about mitigating this type of issue (as a consumer), you really should be specifying name servers from different providers. Your primary DNS server can be from dnsimple/zerigo/dnsmadeeasy and your secondary can be route53, or you could run your own.<p>The only problem seems to be keeping them in sync. Seems like you'd have to poll the primary (using whatever API it exposes) to update the secondary.<p>Mostly thinking out loud, surely someone more experienced could provide better guidance?
评论 #4280710 未加载
jbarham将近 13 年前
I run a DNS hosting service (SlickDNS, www.slickdns.com) and have seen a spike in signups today as a direct result of the Zerigo DDOS attack.<p>I can't claim that SlickDNS is invulnerable to DDOS attack, but FWIW it does run tinydns name servers which have good performance and excellent security. So if you're impacted by the Zerigo outage, feel free to check out SlickDNS. There's a 30-day free trial with all plans and record updates are pushed through to all the name servers in under 5 seconds.
评论 #4280543 未加载
评论 #4280487 未加载
_phred将近 13 年前
Apparently no ETA for restore as of 2 hours ago: <a href="https://twitter.com/zerigo/status/227322909230768128" rel="nofollow">https://twitter.com/zerigo/status/227322909230768128</a>
gaia将近 13 年前
Best thing Zerigo could do for their customers at this point is export all zone information and email it to them or make available for DL. I have a feeling this is going to be a long outage. In the meanwhile, here is a great list of free DNS providers (dont get caught without a secondary DNS provider): <a href="http://www.lowendtalk.com/wiki/free-dns-providers" rel="nofollow">http://www.lowendtalk.com/wiki/free-dns-providers</a>
metalruler将近 13 年前
I've been seeing a lot of reflector attacks in the past couple of weeks, where the attacker sends a relatively small query for a valid domain that will return a large reply. The trick is that they spoof the source IP, so the DNS reply goes to the victim.<p>I ended up hacking something together to firewall any IPs which sent more than 1000 requests in a short period of time.
评论 #4327948 未加载
评论 #4281619 未加载
AdamGibbins将近 13 年前
And this is why I use Route 53, I'm a lot more confident in Amazon's abilities to mitigate DDoS attacks.<p>Which really sucks, DDoS are really hard to combat and Zerigo are an awesome company.
manveru将近 13 年前
Well, that explains why my wife woke me up complaining about half the internet not working. Our ISP is 3 (drei.at) and she was using their DNS, guess there are issues all over Europe.
slig将近 13 年前
What are the main advantages of paying for DNS hosting like Zerigo or SlickDNS instead of using the one provided for free with web host companies (E.g. Linode's DNS Manager)?
评论 #4280674 未加载
评论 #4280546 未加载
sleighboy将近 13 年前
US-Based customer here. Our DNS just started working again.
Uchikoma将近 13 年前
Running with DNSMadeEasy, is there a way to integrate it with Route 53 through AXFR to have two providers?
评论 #4281055 未加载
评论 #4281056 未加载
piggity将近 13 年前
Days later and what do we have from them? One solitary email and a few half-assed status page updates.
St-Clock将近 13 年前
This took down services like Fogbugz on demand.
评论 #4281031 未加载
silverlight将近 13 年前
Looks like this took Trello down, too...
评论 #4281050 未加载
PonyGumbo将近 13 年前
Comodo's DNS.com appears to be down too.