DNS Reflection Update and Odd Corrupted DNS Requests, (Wed, Sep 25th)

SANS Internet Storm Center, InfoCON: green 2024-09-25


Occasionally, I tend to check in on what reflective DNS denial of service attacks are doing. We usually see steady levels of attacks. Usually, they attempt to use spoofed requests for ANY records to achieve the highest possible amplification. Currently, I am seeing these two records used (among others):



From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green


Date tagged:

09/25/2024, 16:42

Date published:

09/25/2024, 12:33