Welcome to 96MB, please Login or Create an account to get full access to the forums.
 
Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5

Copy and paste errors? LOL

Offline zhuanyi Posted 03-29-2013, 05:27 AM -
Post: #1
Senior Member
357 Posts
Reputation: 5
I got this email a while ago:

Quote:You are receiving this e-mail because you currently have an active VPS with us and recent events have highlighted a major security issue that could potentially impact you. You must take action now to prevent your VPS from being suspended and from incurring a re-activation fee. If you do not run a DNS server and have confirmed no such service is running on your VPS, then you can ignore the rest of this e-mail. Please double-check your VPS to make sure no DNS servers are running before ignoring this e-mail.
As some of you are aware, there was a recent Distributed Denial of Service attack against a major internet organization that was stated to be larger than any other attack in history. This attack brought to light a large issue that a lot of server owners were previously not aware of. It highlighted the danger of open DNS recursors. While I will not get into detail, you can read more about t he event and the problem here: http://blog.cloudflare.com/the-ddos-that...e-internet
The main purpose of this e-mail is to make all of our VPS clients aware of the danger and to provide a method to eliminate the chance of their VPS being used in such attacks. If you are running a DNS server, such as BIND, you could very likely be a victim of this attack. We ask that all VPS owners please login to your VPS and check to see if any DNS server is running and to ensure that you have recursion disabled for your DNS server. The most common problems are from clients who install control panels like cPanel and Kloxo but are unaware they come bundled with a DNS server.
Each DNS server and setup is different so you will need to find the correct method of disabling recursion on your DNS server.
Th e most widely used DNS server, BIND, can be fixed easily by editing the /etc/named.conf file and setting changing "recursion yes;" to "recursion no;" and restart the named service.
We have been seeing a large number of outbound DOS attacks lately from our network which is now causing network issues to all of our clients.

If you have a DNS server running and you don't need it then please remove it.
If you have one running and do need it then please disable recursion.
If you need assistance with your DNS server then please turn off your VPS and open a ticket so we can help you.
If you run a DNS service and require recursion to be enabled please contact us.

Again, we require that you take action now to prevent further network issues for all of our clients. Any VPS found participating in outbound Denial of Service attacks related to this issue will be suspended and invoiced a re-activation fee. As always, deliberate DOS attacks will result in immediate termination.
Thank you for your time and cooperation in this matter.
-The Secure Dragon Staff-
Secure Dragon LLC.
www.SecureDragon.net

And few minutes later, this is what I saw:

Quote:Hello Damian,

You are receiving this e-mail because you currently have an active VPS with us and recent events have highlighted a major security issue that could potentially impact you. You must take action now to prevent your VPS from being suspended. If you do not run a DNS server and have confirmed no such service is running on your VPS, then you can ignore the rest of this e-mail. Please double-check your VPS to make sure no DNS servers are running before ignoring this e-mail.

As some of you are aware, there was a recent Distributed Denial of Service attack against a major internet organization that was stated to be larger than any other attack in history. This attack brought to light a large issue that a lot of server owners were previously not aware of. It highlighted the danger of open DNS recursors. While I will not get into detail, you can read more about the event and the problem here: http://blog.cloudflare.com/the-ddos-that...e-internet

The main purpose of this e-mail is to make all of our VPS clients aware of the danger and to provide a method to eliminate the chance of their VPS being used in such attacks. If you are running a DNS server, such as BIND, you could very likely be a victim of this attack. We ask that all VPS owners please login to your VPS and check to see if any DNS server is running and to ensure that you have recursion disabled for your DNS server. The most common problems are from clients who install control panels like cPanel and Kloxo but are unaware they come bundled with a DNS server.

Each DNS server and setup is different so you will need to find the correct method of disabling recursion on your DNS server.

The most widely used DNS server, BIND, can be fixed easily by editing the /etc/named.conf file and setting changing "recursion yes;" to "recursion no;" and restart the named service.

If you have a DNS server running and you don't need it then please remove it.
If you have one running and do need it then please disable recursion.
If you need assistance with your DNS server then please turn off your VPS and open a ticket so we can help you.
If you run a DNS service and require recursion to be enabled please contact us.

Again, we require that you take action now to prevent further network issues for all of our clients. Any VPS found participating in outbound Denial of Service attacks related to this issue will be suspended. As always, deliberate DOS attacks will result in immediate termination.

Thank you for your time and cooperation in this matter.

-Damian Harouff
IPXcore LLC

And you read it right, it was actually sent by IPXcore...

Guess they copied and pasted too fast, LOL Smile
Back to top Find Quote
Offline rds100 Posted 03-29-2013, 05:38 AM -
Post: #2
Junior Member
18 Posts
Reputation: 0
Haha Smile
Still it's a little harsh. They should probably verify who is running open resolver and only send the notice to them. No need to freak out innocent users who might not even know what is bind or recursion.
Back to top Find Quote
Offline zhuanyi Posted 03-29-2013, 06:06 AM -
Post: #3
Senior Member
357 Posts
Reputation: 5
(03-29-2013, 05:38 AM)rds100 Wrote: Haha Smile
Still it's a little harsh. They should probably verify who is running open resolver and only send the notice to them. No need to freak out innocent users who might not even know what is bind or recursion.

I think they just don't want to get blamed for logging into customer's VPS and checking on the data.
Back to top Find Quote
Offline rds100 Posted 03-29-2013, 06:18 AM -
Post: #4
Junior Member
18 Posts
Reputation: 0
There is no need to login, just scan it from the outside. If it replies to recursive queries - open a ticket. If it doesn't reply - then all is well.
Back to top Find Quote
Offline mikho Posted 03-29-2013, 09:59 PM -
Post: #5
official slacker
42 Posts
Reputation: 0
I did scan my vps with both providers to be sure that I hadn't installed a dns server by mistake.

-_- www.lowendguide.com -_- the guides to administer your lowend vps
Like on Facebook and follow on Twitter
Back to top WWW Find Quote
Offline coreymanshack Posted 05-07-2013, 09:52 AM -
Post: #6
Member
79 Posts
Reputation: 0
That's unneeded work for an unmanaged provider isn't it?
Back to top Find Quote


Forum Jump:

User(s) browsing this thread
1 Guest(s)

© 2012 96MB

Community software by MyBB

Premium Theme by ThemeFreak