ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    IoT devices Used in DDoS Attacks

    Water Closet
    iot security internet of things ddos bbc
    12
    49
    6.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      scottalanmiller @Dashrender
      last edited by

      @Dashrender said in IoT devices Used in DDoS Attacks:

      @coliver said in IoT devices Used in DDoS Attacks:

      @scottalanmiller said in IoT devices Used in DDoS Attacks:

      That's not a viable DDoS vector as you just move.

      I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

      I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

      No different than your EHR moving from Dyn to CloudFlare. Would take like five minutes, literally.

      D 1 Reply Last reply Reply Quote 0
      • D
        dafyre @scottalanmiller
        last edited by

        @scottalanmiller said in IoT devices Used in DDoS Attacks:

        @Dashrender said in IoT devices Used in DDoS Attacks:

        @coliver said in IoT devices Used in DDoS Attacks:

        @scottalanmiller said in IoT devices Used in DDoS Attacks:

        That's not a viable DDoS vector as you just move.

        I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

        I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

        No different than your EHR moving from Dyn to CloudFlare. Would take like five minutes, literally.

        But then it takes hours for those changes to propogate worldwide, doesn't it? Generally I've seen minutes, but it's usually half an hour at best, and I've seen it take as long as 48 hours at worst.

        C S T 3 Replies Last reply Reply Quote 0
        • C
          coliver @Dashrender
          last edited by

          @Dashrender said in IoT devices Used in DDoS Attacks:

          @coliver said in IoT devices Used in DDoS Attacks:

          @scottalanmiller said in IoT devices Used in DDoS Attacks:

          That's not a viable DDoS vector as you just move.

          I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

          I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

          IIRC, and I probably don't, but doesn't Cloudflare do distributed DNS on their own? So a DDoS attack against their DNS infrastructure would be ineffective.

          D 1 Reply Last reply Reply Quote 0
          • C
            coliver @dafyre
            last edited by

            @dafyre said in IoT devices Used in DDoS Attacks:

            @scottalanmiller said in IoT devices Used in DDoS Attacks:

            @Dashrender said in IoT devices Used in DDoS Attacks:

            @coliver said in IoT devices Used in DDoS Attacks:

            @scottalanmiller said in IoT devices Used in DDoS Attacks:

            That's not a viable DDoS vector as you just move.

            I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

            I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

            No different than your EHR moving from Dyn to CloudFlare. Would take like five minutes, literally.

            But then it takes hours for those changes to propogate worldwide, doesn't it? Generally I've seen minutes, but it's usually half an hour at best, and I've seen it take as long as 48 hours at worst.

            Depends on the TTL.

            1 Reply Last reply Reply Quote 1
            • S
              scottalanmiller @dafyre
              last edited by

              @dafyre said in IoT devices Used in DDoS Attacks:

              @scottalanmiller said in IoT devices Used in DDoS Attacks:

              @Dashrender said in IoT devices Used in DDoS Attacks:

              @coliver said in IoT devices Used in DDoS Attacks:

              @scottalanmiller said in IoT devices Used in DDoS Attacks:

              That's not a viable DDoS vector as you just move.

              I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

              I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

              No different than your EHR moving from Dyn to CloudFlare. Would take like five minutes, literally.

              But then it takes hours for those changes to propogate worldwide, doesn't it? Generally I've seen minutes, but it's usually half an hour at best, and I've seen it take as long as 48 hours at worst.

              Just a few minutes, generally. At least for most of the world. So you'd solve the 90% within ten minutes, 99% within the hour.

              1 Reply Last reply Reply Quote 2
              • D
                Dashrender @coliver
                last edited by

                @coliver said in IoT devices Used in DDoS Attacks:

                @Dashrender said in IoT devices Used in DDoS Attacks:

                @scottalanmiller said in IoT devices Used in DDoS Attacks:

                Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                Not if they buy their domain name from Dyn also.

                You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                I understand that, but IF they did, and Dyn was inaccessible, then the EHR provider would not be able to change it until either the attack was mitigated/over or the EHR vendor got someone one the phone at Dyn - but I'm not sure that would even matter... wouldn't the root hints still have to talk to Dyn to get the SOA for the EHR vendor? or is the SOA stored in the root hints, I'm fuzzy on that part.

                1 Reply Last reply Reply Quote 0
                • D
                  Dashrender @scottalanmiller
                  last edited by

                  @scottalanmiller said in IoT devices Used in DDoS Attacks:

                  @coliver said in IoT devices Used in DDoS Attacks:

                  @Dashrender said in IoT devices Used in DDoS Attacks:

                  @scottalanmiller said in IoT devices Used in DDoS Attacks:

                  Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                  Not if they buy their domain name from Dyn also.

                  You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                  And it is insanely recommended that you never buy the domain from one and get DNS from the same one. Those two should never overlap. That's how you lose control of your systems.

                  Personally, I had never heard that until I saw your postings on SW. So while I understand this to be true now, I'm not sure where new IT persons would learn about it short of reading a post somewhere online. I suppose it could have been taught at ITT 😜

                  C S 2 Replies Last reply Reply Quote 0
                  • T
                    travisdh1 @dafyre
                    last edited by

                    @dafyre said in IoT devices Used in DDoS Attacks:

                    @scottalanmiller said in IoT devices Used in DDoS Attacks:

                    @Dashrender said in IoT devices Used in DDoS Attacks:

                    @coliver said in IoT devices Used in DDoS Attacks:

                    @scottalanmiller said in IoT devices Used in DDoS Attacks:

                    That's not a viable DDoS vector as you just move.

                    I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

                    I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

                    No different than your EHR moving from Dyn to CloudFlare. Would take like five minutes, literally.

                    But then it takes hours for those changes to propogate worldwide, doesn't it? Generally I've seen minutes, but it's usually half an hour at best, and I've seen it take as long as 48 hours at worst.

                    Yeah, if you know of a move ahead of time, you can change the TTL to say, 15 minutes, and really speed that up. Doesn't help with something hitting you out of the blue tho.

                    1 Reply Last reply Reply Quote 1
                    • C
                      coliver @Dashrender
                      last edited by

                      @Dashrender said in IoT devices Used in DDoS Attacks:

                      @scottalanmiller said in IoT devices Used in DDoS Attacks:

                      @coliver said in IoT devices Used in DDoS Attacks:

                      @Dashrender said in IoT devices Used in DDoS Attacks:

                      @scottalanmiller said in IoT devices Used in DDoS Attacks:

                      Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                      Not if they buy their domain name from Dyn also.

                      You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                      And it is insanely recommended that you never buy the domain from one and get DNS from the same one. Those two should never overlap. That's how you lose control of your systems.

                      Personally, I had never heard that until I saw your postings on SW. So while I understand this to be true now, I'm not sure where new IT persons would learn about it short of reading a post somewhere online. I suppose it could have been taught at ITT 😜

                      I hear University of Pheonix has you covered 😜

                      1 Reply Last reply Reply Quote 1
                      • D
                        Dashrender @coliver
                        last edited by

                        @coliver said in IoT devices Used in DDoS Attacks:

                        @Dashrender said in IoT devices Used in DDoS Attacks:

                        @coliver said in IoT devices Used in DDoS Attacks:

                        @scottalanmiller said in IoT devices Used in DDoS Attacks:

                        That's not a viable DDoS vector as you just move.

                        I don't understand how this was such a big outage. DNS is designed to be resilient because of its simplicity. Why companies are still only using a single DNS provider is beyond me.

                        I only use a single DNS provider. I use Cloudflare. I did buy my domain name from someone else though.. so moving it like scott said would be typically pretty fast if Cloudflare was under attack.

                        IIRC, and I probably don't, but doesn't Cloudflare do distributed DNS on their own? So a DDoS attack against their DNS infrastructure would be ineffective.

                        I don't follow. The SOA still has to be on the listed IPs. If all of the listed IPs are being attacked at once, you can't get away from it.

                        In the case of Dyn, I would assume either A) all of the IPs are behind a singular pipe (horrible design) or there was only one.

                        1 Reply Last reply Reply Quote 0
                        • D
                          Dashrender
                          last edited by

                          My EMR vendor has now expanded to 3 DNS providers, and from what I can tell, at least one of them is based in Europe.

                          1 Reply Last reply Reply Quote 1
                          • S
                            scottalanmiller @Dashrender
                            last edited by

                            @Dashrender said in IoT devices Used in DDoS Attacks:

                            @scottalanmiller said in IoT devices Used in DDoS Attacks:

                            @coliver said in IoT devices Used in DDoS Attacks:

                            @Dashrender said in IoT devices Used in DDoS Attacks:

                            @scottalanmiller said in IoT devices Used in DDoS Attacks:

                            Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                            Not if they buy their domain name from Dyn also.

                            You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                            And it is insanely recommended that you never buy the domain from one and get DNS from the same one. Those two should never overlap. That's how you lose control of your systems.

                            Personally, I had never heard that until I saw your postings on SW. So while I understand this to be true now, I'm not sure where new IT persons would learn about it short of reading a post somewhere online. I suppose it could have been taught at ITT 😜

                            It's not for you to have heard of. It's nothing to do with IT. It's a fundamental business concern. Any business manager should just know this. It's not a technical thing (well, it is... single point of failure, general risk) it's purely standard business knowledge. Really, it's just common sense. The whole system exists the way that it does to make sure you are never stuck with one company owning you.

                            D 1 Reply Last reply Reply Quote 0
                            • D
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said in IoT devices Used in DDoS Attacks:

                              @Dashrender said in IoT devices Used in DDoS Attacks:

                              @scottalanmiller said in IoT devices Used in DDoS Attacks:

                              @coliver said in IoT devices Used in DDoS Attacks:

                              @Dashrender said in IoT devices Used in DDoS Attacks:

                              @scottalanmiller said in IoT devices Used in DDoS Attacks:

                              Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                              Not if they buy their domain name from Dyn also.

                              You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                              And it is insanely recommended that you never buy the domain from one and get DNS from the same one. Those two should never overlap. That's how you lose control of your systems.

                              Personally, I had never heard that until I saw your postings on SW. So while I understand this to be true now, I'm not sure where new IT persons would learn about it short of reading a post somewhere online. I suppose it could have been taught at ITT 😜

                              It's not for you to have heard of. It's nothing to do with IT. It's a fundamental business concern. Any business manager should just know this. It's not a technical thing (well, it is... single point of failure, general risk) it's purely standard business knowledge. Really, it's just common sense. The whole system exists the way that it does to make sure you are never stuck with one company owning you.

                              LOL, well except that your registrar does if they decide not to place nice.. but hopefully they would be sued out of existence if that happened.

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                scottalanmiller @Dashrender
                                last edited by

                                @Dashrender said in IoT devices Used in DDoS Attacks:

                                @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                @Dashrender said in IoT devices Used in DDoS Attacks:

                                @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                @coliver said in IoT devices Used in DDoS Attacks:

                                @Dashrender said in IoT devices Used in DDoS Attacks:

                                @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                                Not if they buy their domain name from Dyn also.

                                You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                                And it is insanely recommended that you never buy the domain from one and get DNS from the same one. Those two should never overlap. That's how you lose control of your systems.

                                Personally, I had never heard that until I saw your postings on SW. So while I understand this to be true now, I'm not sure where new IT persons would learn about it short of reading a post somewhere online. I suppose it could have been taught at ITT 😜

                                It's not for you to have heard of. It's nothing to do with IT. It's a fundamental business concern. Any business manager should just know this. It's not a technical thing (well, it is... single point of failure, general risk) it's purely standard business knowledge. Really, it's just common sense. The whole system exists the way that it does to make sure you are never stuck with one company owning you.

                                LOL, well except that your registrar does if they decide not to place nice.. but hopefully they would be sued out of existence if that happened.

                                They don't have that option. It's a requirement of the process.

                                D 1 Reply Last reply Reply Quote 0
                                • D
                                  Dashrender @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                  @Dashrender said in IoT devices Used in DDoS Attacks:

                                  @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                  @Dashrender said in IoT devices Used in DDoS Attacks:

                                  @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                  @coliver said in IoT devices Used in DDoS Attacks:

                                  @Dashrender said in IoT devices Used in DDoS Attacks:

                                  @scottalanmiller said in IoT devices Used in DDoS Attacks:

                                  Ah, the cacheing failed from there? But they could move to another provider in, like, five minutes. Faster than the TTL on the records. That's not a viable DDoS vector as you just move.

                                  Not if they buy their domain name from Dyn also.

                                  You can purchase domain names from whomever it doesn't stop you from doing DNS from a different vendor or internally.

                                  And it is insanely recommended that you never buy the domain from one and get DNS from the same one. Those two should never overlap. That's how you lose control of your systems.

                                  Personally, I had never heard that until I saw your postings on SW. So while I understand this to be true now, I'm not sure where new IT persons would learn about it short of reading a post somewhere online. I suppose it could have been taught at ITT 😜

                                  It's not for you to have heard of. It's nothing to do with IT. It's a fundamental business concern. Any business manager should just know this. It's not a technical thing (well, it is... single point of failure, general risk) it's purely standard business knowledge. Really, it's just common sense. The whole system exists the way that it does to make sure you are never stuck with one company owning you.

                                  LOL, well except that your registrar does if they decide not to place nice.. but hopefully they would be sued out of existence if that happened.

                                  They don't have that option. It's a requirement of the process.

                                  That's like a requirement of the process that Certificate authorities aren't suppose to mint certs for companies that people don't own.. but then you have horrible systems and these things happen anyhow 😛

                                  1 Reply Last reply Reply Quote 1
                                  • ObsolesceO
                                    Obsolesce
                                    last edited by Obsolesce

                                    Where the complexity comes in, is that it's not just simply one IP address being matched to a single domain name.

                                    If that were the case, there wouldn't have been any outages for these websites.

                                    The problem is that there's thousands of IP addresses that are mapped to tens or hundreds of domain names for a single domain, for example, load balancing and other supporting services.

                                    Visit facebook.com and record all network activity. It's not just facebook.com you see, there's x.facebook.com, xyz.facebook.com, etc... It's also not the same IP address for everyone. It get's very complex.

                                    If the authoritative name server for a domain or several domains that support a single domain becomes unavailable, things will be fine until the TTLs expire. Once that happens on the DNS servers down the chain, you don't get the name resolution anymore, and those dns servers can no longer find a path to resolution.

                                    When you combine that with all the other interworkings of a domain, it can be awhile until things get better, even if the attacked name servers get better.

                                    How many of you have ever bought a single domain name and see the message it may take up to 48 hours or whatever to propagate?

                                    The above is pretty a pretty basic explanation and understanding, but I'm just trying to get my point across without making a massive wall of text.

                                    1 Reply Last reply Reply Quote 2
                                    • D
                                      dafyre
                                      last edited by

                                      @Tim_G does this help:

                                      https://media.giphy.com/media/3o7TKnoGIyWgMIMVMY/giphy.gif

                                      1 Reply Last reply Reply Quote 0
                                      • ChrisLC
                                        ChrisL @scottalanmiller
                                        last edited by

                                        The machines are revolting!

                                        Destroys toaster

                                        S 1 Reply Last reply Reply Quote 1
                                        • S
                                          scottalanmiller @ChrisL
                                          last edited by

                                          @ChrisL said in IoT devices Used in DDoS Attacks:

                                          The machines are revolting!

                                          Destroys toaster

                                          Or... the toaster destroys YOU!

                                          1 Reply Last reply Reply Quote 1
                                          • S
                                            scottalanmiller
                                            last edited by

                                            Gives a new meaning to "you are toast".

                                            ChrisLC 1 Reply Last reply Reply Quote 2
                                            • 1
                                            • 2
                                            • 3
                                            • 3 / 3
                                            • First post
                                              Last post