If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
(Stogie @ Feb. 14 2009,15:14) Nope... Bam has seen to that!
That€™s because we run our own private nameserver network that will answer only to zone file queries about domains we host. I€™ve never liked using any Open DNS servers€¦ now you know why!
Public or €œOpen DNS€ nameservers that anyone in the world can query for domains is not authoritative. This can cause an excessive load on the DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address which is just what we saw with this DNS dDOS attack.
Best advice€¦ run your own DNS€¦ it€™s not that hard to do and easy these days to setup under cPanel.
(Stogie @ Feb. 14 2009,15:14) Nope... Bam has seen to that!
That€™s because we run our own private nameserver network that will answer only to zone file queries about domains we host. I€™ve never liked using any Open DNS servers€¦ now you know why!
Public or €œOpen DNS€ nameservers that anyone in the world can query for domains is not authoritative. This can cause an excessive load on the DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address which is just what we saw with this DNS dDOS attack.
Best advice€¦ run your own DNS€¦ it€™s not that hard to do and easy these days to setup under cPanel.
I wish I understood that. lol I know just about every aspect of this industry except the hosting side.
I did copy and paste and send it on. Thanks for the info bam!
Any idea why the hosting companies don't just do it this way out of the gate? Is there a downside to it?
we also have persistent attacks here in Switzerland on websites related to sex services (i.e. escorting, brothels, etc.)
a couple went down 2 days ago.
I also run my own DNS server - but I think I could't withstand a traditional DDoS.
Comment