Spammers Target DNS Servers
Posted by Miles Evans

It would seem for the last few days a large website I maintain (a 3 server operation) was down for the count. I quickly realized the problem had nothing to do with me but with my registrar joker.com. According to the website they’re nameservers were under a DoS style attack:
"Joker.com currently experiences massive distributed denial of service attacks against nameservers. This affects DNS resolution of Joker.com itself, and also domains which make use of Joker.com nameservers. We are very sorry for this issue, but we are working hard for a permanent solution."
This isn’t the first time I have seen this as it happened to VeriSign earlier this year. Basically a spammer uses your nameserver for mailing and it overloads the machine. Having a DNS server open for recursion is the equivilant of running an open SMTP relay. So if you run your own nameservers you might want to take a look at this.
You can see more information on the technical aspect of these attacks at this thread on WMW.
Cnet has a great article about this problem as well for the layman.
Up to 80% of spam targetted at Internet users in North America and Europe is generated by a hard-core group of known professional spammers whose names, aliases and operations are documented in Spamhaus’ Register Of Known Spammers (ROKSO) database.
For very detailed information on the scum bags behind the vast majority of internet spam check out Brian McWilliams Spam Kings blog. The photo above is a collage of the top spam A-listers. I hope they rot.
Posted March 25, 2006 05:14 AM | Permalink | Trackback URL | DIGG!

