[176172] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

DNS Lookup - Filter "localhost"

daemon@ATHENA.MIT.EDU (Radke, Justin)
Mon Nov 17 16:11:20 2014

X-Original-To: nanog@nanog.org
Date: Mon, 17 Nov 2014 13:11:11 -0800
From: "Radke, Justin" <jradke@canbytel.com>
To: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org

This past weekend we started receiving bursts of lookups on our DNS server
for "localhost." We blocked our subscriber abusing this lookup (most
assuredly malware and not intentional) but curious what safeguards you put
in place for DOS attacks on your DNS servers.

1. As an ISP do you see a problem with blocking localhost on your DNS
servers? (we don't see any validity to these requests but checking with you
to see if we've overlooked something).
2. Do you have an actual localhost zone that issues 127.0.0.1?
3. Do you block >512 Bytes DNS requests?
4. Do you block non-UDP DNS requests or rate-limit requests?
5. Anything else you block/filter on your DNS servers?

-=JGR

home help back first fref pref prev next nref lref last post