OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: recursive DNS servers DDoS as a growing DDoS problem

From: Robert Story (rstory-l2006.revelstone.com)
Date: Tue Mar 14 2006 - 05:52:37 CST


On Tue, 7 Mar 2006 19:26:19 +0200 Ventsislav wrote:
VG> Are you sure about that amplification process??

Yes.

VG> In the scenario you describe, I cannot see any actual amplification...

The amplification isn't in the number of hosts responding, but in packet size.
A very small DNS request packet results in a huge response packet.