# This domain does not belong to me # (yet)
Well how about that. Some one bought me a domain name! Maybe I can seize it... ;-)
If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.
If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.
IPtables:
There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.
U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x17444e53 && 0x2c&0xDFDFDFDF=0x414d504c && 0x30&0xDFDFDFDF=0x49464943 && 0x34&0xDFDFDFDF=0x4154494f && 0x38&0xDFDFDFDF=0x4e415454 && 0x3c&0xDFDFDFDF=0x41434b53 && 0x40&0xFFDFDFFF=0x02434300" -j DROP -m comment --comment "DROP DNS Q dnsamplificationattacks.cc"
More U32 rules can be found here:
https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt
String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 68 --algo bm --hex-string '|17646e73616d706c696669636174696f6e61747461636b7302636300|' -j DROP -m comment --comment "DROP DNS Q dnsamplificationattacks.cc"
More Iptables rules for the STRING module can be found here:
https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt
Source:
80.82.65.237 - Ecatel
Name server:
;; ANSWER SECTION:
dnsamplificationattacks.cc. 9533 IN NS b.dns.gandi.net.
dnsamplificationattacks.cc. 9533 IN NS a.dns.gandi.net.
dnsamplificationattacks.cc. 9533 IN NS c.dns.gandi.net.
Response:
A 246
NS 3
SOA 1
Rsize 4072
Whois
Whois Server Version 2.0
Domain names can now be registered with many different competing registrars.
Go to http://registrar.verisign-grs.com/whois/ for detailed information.
Domain Name: DNSAMPLIFICATIONATTACKS.CC
Domain ID: 108517593
Whois Server: whois.gandi.net
Referral URL: http://www.gandi.net
Updated Date: 2013-12-04T14:44:17Z
Creation Date: 2013-12-04T14:44:16Z
Expiration Date: 2014-12-04T14:44:16Z
Sponsoring Registrar: GANDI SAS
Sponsoring Registrar IANA ID: 81
Domain Status: CLIENT-XFER-PROHIBITED
Name Server: A.DNS.GANDI.NET
Name Server: B.DNS.GANDI.NET
Name Server: C.DNS.GANDI.NET
DNSSEC: Unsigned delegation
>>> Last update of whois database: 2013-12-04T22:28:30Z <<<
NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the
expiration date of the domain name registrant's agreement with the
sponsoring registrar. Users may consult the sponsoring registrar's
Whois database to view the registrar's reported date of expiration
for this registration.
The Registry database contains ONLY .cc, .tv, and .jobs domains
and Registrars.
--- #YAML:1.0
# GANDI Registrar whois database for .COM, .NET, .ORG., .INFO, .BIZ, .NAME
#
domain: dnsamplificationattacks.cc
reg_created: 2013-12-04 19:44:16
expires: 2014-12-04 19:44:16
created: 2013-12-04 20:44:16
changed: 2013-12-04 20:55:28
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
admin-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
tech-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
bill-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
Once the domain will stop working give it to you
ReplyDelete