Tuesday, October 31. 2006
For the most part, things have levelled out on the DOS attack. Again, I note that most of the pain was felt by members using third party registrars who didn't have the full 6 nameservers in their DNS delegation.
Status as follows, all servers are functioning normally except certain parts of the net may have limited visibility to one of the following:
n1.easydns.com - up, but being null routed by shaw.ca, people on shaw or transiting across shaw can't see ns1
remote2.easydns.com - up but being null routed by cogent, we also changed the IP address of remote2 during the attack, it was switched from 205.210.42.20 to 205.210.42.19, but will respond on either IP.
ns6.easydns.org - null routed by rackspace and now renumbered onto the prolexic network temporarily.
We expect the null routes to begin clearing over the course of the day wednesday.
ns2.easydns.com remote1.easydns.com and ns3.easydns.org are all up and functional at the time of writing.
Many thanks to our members for being patient and commenting constructively.
With apologies for not posting earlier about this, but this morning the DOS attack expanded to all of our nameservers, however we have managed to maintain DNS availability.
So far every single customer who has reported a problem with DNS availability over the course of the DOS attack has, upon inspection of their domain's nameserver delegation, only been delegated to a subset of the full nameserver cluster.
In many cases users using third-party registrars were still only delegated to 2 nameservers. This misses much of the benefit having an expanded nameserver cluster exposes your domain to elevated risk of DNS-outage during events such as this.
So please, if you're using an external registrar, check your delegation and make sure your domains are delegated to all 6 of our nameservers:
NS1.EASYDNS.COM
NS2.EASYDNS.COM
NS3.EASYDNS.ORG
NS6.EASYDNS.NET
REMOTE1.EASYDNS.COM
REMOTE2.EASYDNS.COM
This morning we experienced a DoS attack directed against our DNS
infrastructure. We have been working with our various providers to
quell the attack and keep easyDNS services online.
Currently all services are online and responding.
Some customers may experience issues using ns6.easydns.net , as
our Rackspace datacenter has taken measures which null routed the
IP of this host.
Monday, October 30. 2006
This morning's DOS attack was directed against ns1.easydns.com and is an ongoing event. Some upstream networks from our Q9 datacenter (Toronto) are enacting counter-measures which will render NS1 unreachable to users on the other side of those networks (examples are Teleglobe and Cogent).
The rest of the nameservers (Miami, Phoenix, Texas, Toronto2 and London, UK) are unaffected, overall DNS availability was not affected by this attack, however email and web forwarding was impacted during the initial attack phase. Please note that no email was lost, only delayed and email forwarding times returned to normal very quickly.
More as it comes in.
We are currently experiencing a DoS attack against our DNS and
Email infrastructure. The nature of the attack has been identified
and we are working with our providers to restore all easyDNS
services.
We do apologize for the inconvenience.
Sunday, October 22. 2006
We are seeing intermittent delays when forwarding to Shaw.ca's primary
mail server, idcmail.shaw.ca from smtp.easydns.com.
We have mitigated the problem by forwarding mail destined to Shaw.ca through other mail
servers.
We believe the problem is a temporary issue at Shaw's mail gateway.