<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: XName.org down: largest DDoS they ever had</title>
	<atom:link href="http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html/feed" rel="self" type="application/rss+xml" />
	<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html</link>
	<description>Science, Society, Programming and Hobbies</description>
	<pubDate>Tue, 02 Dec 2008 01:51:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Xname is down again &#187; Autarchy of the Private Cave</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-69275</link>
		<dc:creator>Xname is down again &#187; Autarchy of the Private Cave</dc:creator>
		<pubDate>Sun, 25 May 2008 10:06:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-69275</guid>
		<description>[...] XName is down again [...]</description>
		<content:encoded><![CDATA[<p>[...] XName is down again [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27601</link>
		<dc:creator>Bogdan</dc:creator>
		<pubDate>Wed, 10 Oct 2007 20:03:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27601</guid>
		<description>&lt;blockquote cite="xname-availability"&gt;
Operations came back to normal at 12:00 AM today.

ns1 was up during the whole DDoS, and ns0 was off for all global access - but was accessible for our network peers.

To face these recurring problems, we'll set up shortly a third DNS server (under active testing at the moment), and we're studying how to build larger solutions accordingly with our resources (only from contributors). When done, announces will be done on xname-news mailing list.
&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<blockquote cite="xname-availability"><p>
Operations came back to normal at 12:00 AM today.</p>
<p>ns1 was up during the whole DDoS, and ns0 was off for all global access - but was accessible for our network peers.</p>
<p>To face these recurring problems, we&#8217;ll set up shortly a third DNS server (under active testing at the moment), and we&#8217;re studying how to build larger solutions accordingly with our resources (only from contributors). When done, announces will be done on xname-news mailing list.
</p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aidan</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27497</link>
		<dc:creator>Aidan</dc:creator>
		<pubDate>Tue, 09 Oct 2007 21:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27497</guid>
		<description>&lt;blockquote cite="Bogdan"&gt;Did you check manually, or have some (semi-)automatic means for checking?&lt;/blockquote&gt;

I'm monitoring Ping responses from and DNS requests to ns0 and ns1 using &lt;a href="http://www.nagios.org/" title="Nagios" rel="nofollow"&gt;Nagios&lt;/a&gt;.  I started doing this following the outage on the 1st.

I've subscribed to the xname list but haven't had my e-mail yet so thanks for confirming the problem.

regards,
Aidan</description>
		<content:encoded><![CDATA[<blockquote cite="Bogdan"><p>Did you check manually, or have some (semi-)automatic means for checking?</p></blockquote>
<p>I&#8217;m monitoring Ping responses from and DNS requests to ns0 and ns1 using <a href="http://www.nagios.org/" title="Nagios" rel="nofollow" onclick="javascript:urchinTracker ('/outbound/comment/www.nagios.org');">Nagios</a>.  I started doing this following the outage on the 1st.</p>
<p>I&#8217;ve subscribed to the xname list but haven&#8217;t had my e-mail yet so thanks for confirming the problem.</p>
<p>regards,<br />
Aidan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27495</link>
		<dc:creator>Bogdan</dc:creator>
		<pubDate>Tue, 09 Oct 2007 21:33:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27495</guid>
		<description>Aidan,
thanks for sharing information. Did you check manually, or have some (semi-)automatic means for checking? I didn't notice any problems, but that is because I was too busy to have a look at my sites for several days in a row.

I must say though, that I did get an email. Here it is:
&lt;blockquote&gt;
Dear XName-Availability subscribers,

both ns0 and ns1 DNS servers are under heavy DDoS attack since 4:45 PM
(gmt+2) this afternoon.

The BGP session serving NS0 network is flapping due to a total
saturation of the link, so NS0 is up very intermittently.

ns1 is still online, even if loaded.
&lt;/blockquote&gt;

I got this email on the 9th of October at 23:00 gmt+2 from the XName-Availability mailing list.</description>
		<content:encoded><![CDATA[<p>Aidan,<br />
thanks for sharing information. Did you check manually, or have some (semi-)automatic means for checking? I didn&#8217;t notice any problems, but that is because I was too busy to have a look at my sites for several days in a row.</p>
<p>I must say though, that I did get an email. Here it is:</p>
<blockquote><p>
Dear XName-Availability subscribers,</p>
<p>both ns0 and ns1 DNS servers are under heavy DDoS attack since 4:45 PM<br />
(gmt+2) this afternoon.</p>
<p>The BGP session serving NS0 network is flapping due to a total<br />
saturation of the link, so NS0 is up very intermittently.</p>
<p>ns1 is still online, even if loaded.
</p></blockquote>
<p>I got this email on the 9th of October at 23:00 gmt+2 from the XName-Availability mailing list.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aidan</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27464</link>
		<dc:creator>Aidan</dc:creator>
		<pubDate>Tue, 09 Oct 2007 18:00:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-27464</guid>
		<description>&lt;strong&gt;Possible new attack on XName servers - 9 October 2007&lt;/strong&gt;

DNS resolution from ns0.xname.org was lost at 17:09 BST (16:09 GMT).  ICMP was lost at 16:05 BST.

ns1.xname.org is still resolving although ICMP has been intermittent since 16:59 BST.

I have not received any information from XName.  This is information I have gathered through my own monitoring.

HTH
Aidan</description>
		<content:encoded><![CDATA[<p><strong>Possible new attack on XName servers - 9 October 2007</strong></p>
<p>DNS resolution from ns0.xname.org was lost at 17:09 BST (16:09 GMT).  ICMP was lost at 16:05 BST.</p>
<p>ns1.xname.org is still resolving although ICMP has been intermittent since 16:59 BST.</p>
<p>I have not received any information from XName.  This is information I have gathered through my own monitoring.</p>
<p>HTH<br />
Aidan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DNS troubles? &#187; Autarchy of the Private Cave</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-24155</link>
		<dc:creator>DNS troubles? &#187; Autarchy of the Private Cave</dc:creator>
		<pubDate>Mon, 01 Oct 2007 19:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-24155</guid>
		<description>[...] Update: this is in fact XName-related problem: they are again under DDoS attack. [...]</description>
		<content:encoded><![CDATA[<p>[...] Update: this is in fact XName-related problem: they are again under DDoS attack. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HTTP caching: universal approach and sample code &#187; Autarchy of the Private Cave</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-5068</link>
		<dc:creator>HTTP caching: universal approach and sample code &#187; Autarchy of the Private Cave</dc:creator>
		<pubDate>Thu, 03 May 2007 14:52:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-5068</guid>
		<description>[...] Now, let's move on to actual caching. The simplest and quite reliable method of identifying any object within your cache is md5(url) - that is, the hash of the request URL. Note, that you might want to hash not the complete URL (starting with http://), but only the part after the TLD's slash, e.g. for complete URL http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html you would hash only the "xnameorg-down-largest-ddos-they-ever-had.html" part (or "2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html", if the filename part of the path might be non-unique). Evidently, this will save you from generating cache both for "http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html" and for "http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html" (differing only in "www." part). [...]</description>
		<content:encoded><![CDATA[<p>[...] Now, let&#8217;s move on to actual caching. The simplest and quite reliable method of identifying any object within your cache is md5(url) - that is, the hash of the request URL. Note, that you might want to hash not the complete URL (starting with <a href="http://" rel="nofollow" onclick="javascript:urchinTracker ('/outbound/comment/');">http://</a>), but only the part after the TLD&#8217;s slash, e.g. for complete URL <a href="http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html" rel="nofollow" >http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html</a> you would hash only the &#8220;xnameorg-down-largest-ddos-they-ever-had.html&#8221; part (or &#8220;2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html&#8221;, if the filename part of the path might be non-unique). Evidently, this will save you from generating cache both for &#8220;http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html&#8221; and for &#8220;http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html&#8221; (differing only in &#8220;www.&#8221; part). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Василий Борисович Черский</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-120</link>
		<dc:creator>Василий Борисович Черский</dc:creator>
		<pubDate>Tue, 02 Jan 2007 18:26:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-120</guid>
		<description>на приватний канал IRC где я бывал, а сотовой админитратор сказал :

Oct 27 06:14:29   xname : dead
Oct 27 06:15:09   DDoS depuis hier
Oct 27 06:15:20   dès qu'on essaye de remttre les NS up on se fait DDoS
Oct 27 06:16:21   UDP flood sur le port 53 des deux NS
Oct 27 06:16:46   donc clairement non filtrable
Oct 27 06:17:01   sur 10000 à 30000 ip sources différentes
Oct 27 06:32:55   bah mercredi on a eu un ddos sur xname en icmp type 0
Oct 27 06:33:04   ca a duré 1h est c'est passé
Oct 27 06:33:05   la...
Oct 27 06:33:14   ca doit être de putains de botnets de merde
Oct 27 06:33:20   qui nous casse les pieds
Oct 27 07:02:12   bon
Oct 27 07:02:13   y a un des connard qui emmerde xname qui est : 213.148.160.20

20.160.148.213.in-addr.arpa domain name pointer dc.natm.ru.

Oct 27 07:02:32   340352 packets en 5 minutes
Oct 27 07:03:39   Xname est down because DDoS depuis hier soir 19h
Oct 27 07:08:22   non en fait... je suis aussi l'admin du reéseau kheops qui herge kazar et xname
Oct 27 07:08:32   et ca c'est  les traces netflow
Oct 27 07:08:40   # bgpctl sh ip bgp as 16301
Oct 27 07:08:40   flags: * = Valid, &#62; = Selected, I = via IBGP, A = Announced
Oct 27 07:08:40   origin: i = IGP, e = EGP, ? = Incomplete
Oct 27 07:08:40   flags destination         gateway          lpref   med aspath origin
Oct 27 07:08:40   *&#62;    84.242.192.0/18     213.163.173.46     100     0 20917 3257 25462 8997 16301 i
Oct 27 07:08:40   *&#62;    213.148.160.0/19    213.163.173.46     100     0 20917 3257 25462 8997 16301 i
Oct 27 07:08:49   vu qu'ils ont deux subnet
Oct 27 07:09:00   je vais refuser toute annonce de l'as16301
Oct 27 07:09:03   et on verra
Oct 27 11:29:45   vt: j'ai 30Mbps qui vient de ces ips : 211.226.22.39, 219.138.151.156, 124.101.96.180, 58.70.87.229, 61.208.120.76, 219.134.185.188, 193.255.70.128, 70.83.237.133
Oct 27 11:50:09   Date flow start          Duration Proto      Src IP Addr:Port          Dst IP Addr:Port   Flags Tos  Packets    Bytes      pps      bps    Bpp Flows
Oct 27 11:50:09   2006-10-27 17:30:00.000   299.000 UDP      211.226.22.39:2344  -&#62;     195.234.42.1:53    ......   0   590592  333.7 M     1975    8.9 M    592  4614
Oct 27 11:50:10   2006-10-27 17:30:00.000   299.000 UDP    219.138.151.156:36082 -&#62;     195.234.42.1:53    .AP...   0   291200  165.8 M      973    4.4 M    597  2275

траффик на графе (у меня граф на другом компьюторе - я тебя сдаю) : 680 Mbit/s

Я отправил E-mail админа natm.ru и мне сказали :
«
From: "Sergey Goncharov" 
Subject: Re: DDoS na XName

Добрый день, Василий.

Да, мы в
Источник уже локализован.

Приносим извинения за беспокойство.

С уважением, Сергей Гончаров
ООО "Новгород Дейтаком", системный администратор
»</description>
		<content:encoded><![CDATA[<p>на приватний канал IRC где я бывал, а сотовой админитратор сказал :</p>
<p>Oct 27 06:14:29   xname : dead<br />
Oct 27 06:15:09   DDoS depuis hier<br />
Oct 27 06:15:20   dès qu&#8217;on essaye de remttre les NS up on se fait DDoS<br />
Oct 27 06:16:21   UDP flood sur le port 53 des deux NS<br />
Oct 27 06:16:46   donc clairement non filtrable<br />
Oct 27 06:17:01   sur 10000 à 30000 ip sources différentes<br />
Oct 27 06:32:55   bah mercredi on a eu un ddos sur xname en icmp type 0<br />
Oct 27 06:33:04   ca a duré 1h est c&#8217;est passé<br />
Oct 27 06:33:05   la&#8230;<br />
Oct 27 06:33:14   ca doit être de putains de botnets de merde<br />
Oct 27 06:33:20   qui nous casse les pieds<br />
Oct 27 07:02:12   bon<br />
Oct 27 07:02:13   y a un des connard qui emmerde xname qui est : 213.148.160.20</p>
<p>20.160.148.213.in-addr.arpa domain name pointer dc.natm.ru.</p>
<p>Oct 27 07:02:32   340352 packets en 5 minutes<br />
Oct 27 07:03:39   Xname est down because DDoS depuis hier soir 19h<br />
Oct 27 07:08:22   non en fait&#8230; je suis aussi l&#8217;admin du reéseau kheops qui herge kazar et xname<br />
Oct 27 07:08:32   et ca c&#8217;est  les traces netflow<br />
Oct 27 07:08:40   # bgpctl sh ip bgp as 16301<br />
Oct 27 07:08:40   flags: * = Valid, &gt; = Selected, I = via IBGP, A = Announced<br />
Oct 27 07:08:40   origin: i = IGP, e = EGP, ? = Incomplete<br />
Oct 27 07:08:40   flags destination         gateway          lpref   med aspath origin<br />
Oct 27 07:08:40   *&gt;    84.242.192.0/18     213.163.173.46     100     0 20917 3257 25462 8997 16301 i<br />
Oct 27 07:08:40   *&gt;    213.148.160.0/19    213.163.173.46     100     0 20917 3257 25462 8997 16301 i<br />
Oct 27 07:08:49   vu qu&#8217;ils ont deux subnet<br />
Oct 27 07:09:00   je vais refuser toute annonce de l&#8217;as16301<br />
Oct 27 07:09:03   et on verra<br />
Oct 27 11:29:45   vt: j&#8217;ai 30Mbps qui vient de ces ips : 211.226.22.39, 219.138.151.156, 124.101.96.180, 58.70.87.229, 61.208.120.76, 219.134.185.188, 193.255.70.128, 70.83.237.133<br />
Oct 27 11:50:09   Date flow start          Duration Proto      Src IP Addr:Port          Dst IP Addr:Port   Flags Tos  Packets    Bytes      pps      bps    Bpp Flows<br />
Oct 27 11:50:09   2006-10-27 17:30:00.000   299.000 UDP      211.226.22.39:2344  -&gt;     195.234.42.1:53    &#8230;&#8230;   0   590592  333.7 M     1975    8.9 M    592  4614<br />
Oct 27 11:50:10   2006-10-27 17:30:00.000   299.000 UDP    219.138.151.156:36082 -&gt;     195.234.42.1:53    .AP&#8230;   0   291200  165.8 M      973    4.4 M    597  2275</p>
<p>траффик на графе (у меня граф на другом компьюторе - я тебя сдаю) : 680 Mbit/s</p>
<p>Я отправил E-mail админа natm.ru и мне сказали :<br />
«<br />
From: &#8220;Sergey Goncharov&#8221;<br />
Subject: Re: DDoS na XName</p>
<p>Добрый день, Василий.</p>
<p>Да, мы в<br />
Источник уже локализован.</p>
<p>Приносим извинения за беспокойство.</p>
<p>С уважением, Сергей Гончаров<br />
ООО &#8220;Новгород Дейтаком&#8221;, системный администратор<br />
»</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chronos</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-119</link>
		<dc:creator>chronos</dc:creator>
		<pubDate>Tue, 02 Jan 2007 10:44:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-119</guid>
		<description>А где об этом сообщали? Я бы добавил сюда подробности...</description>
		<content:encoded><![CDATA[<p>А где об этом сообщали? Я бы добавил сюда подробности&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Василий Борисович Черский</title>
		<link>http://bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-118</link>
		<dc:creator>Василий Борисович Черский</dc:creator>
		<pubDate>Mon, 01 Jan 2007 23:32:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.bogdan.org.ua/2006/10/27/xnameorg-down-largest-ddos-they-ever-had.html#comment-118</guid>
		<description>Кстати, они флудировали Xname из российской ISP в Красноярске :/</description>
		<content:encoded><![CDATA[<p>Кстати, они флудировали Xname из российской ISP в Красноярске :/</p>
]]></content:encoded>
	</item>
</channel>
</rss>
