The DNS Water Torture Attack

  Рет қаралды 11,674

F5 DevCentral

F5 DevCentral

Күн бұрын

Пікірлер: 16
@richtourist
@richtourist 11 ай бұрын
Thank god for F5! What would we do without them!?
@rygelxix
@rygelxix 5 жыл бұрын
Does the AFM have a cache that itself could be flooded to bring it down? Or does it just discard all of these fake requests no further question?
@dronomads
@dronomads 6 жыл бұрын
Awesome explanation John . Can we have a best practice recommendations to configure it on afm . Any guides with guidelines are appreciated
@qsarkiss
@qsarkiss 6 жыл бұрын
Beyond the name of this attack, i like the pen, the glass board & the way John Wagnon draw on it ( and from right to left...except if it is a mirror image with a mirror DevCentral logo on the Polo...is it ? :) ).
@PascalMichkinE
@PascalMichkinE 6 жыл бұрын
It is ! They made specific tshirts for these videos :)
@amirhossein5055
@amirhossein5055 2 жыл бұрын
@monitorinterfaces524
@monitorinterfaces524 4 жыл бұрын
very clear, one Q. F5 will take the hits for the DNS server, Won't this also utilize the box.
@devcentral
@devcentral 4 жыл бұрын
great question! This is why the AFM (Advanced Firewall Manager) can learn the subdomains of your web application and block the attack before it consumes all the resources when requesting illegitimate subdomains.
@thetest6145
@thetest6145 5 жыл бұрын
Bind9 is not installed ubuntu apache is a web server, if cloudflare is using proxy ips, ip server ip addresses are hidden, in which case will the server be exposed to dns attacks? Need to know our attacker web server ip address attacking the DNS?
@devcentral
@devcentral 5 жыл бұрын
Hi there...if I understand the question correctly, you are asking if the attacker needs to know the IP address of your web server in order to attack using DNS Water Torture. This attack specifically targets the authoritative name server that would respond with the proper DNS information for your web server. So, the attack is not directly against the web server. Rather, it's against the name server that tells the Internet how to get to your web server. The idea is that, if the attacker can consume the resources of the authoritative name server for your website, then the name server can't respond to legitimate requests for your web server. Then, users won't be able to access your web server because they weren't given the proper DNS information (IP address) for how to access it. Hope this helps!
@abhaypratap5311
@abhaypratap5311 6 жыл бұрын
Can we deploy a filter in client side or middle to mitigate these kinds of attack...
@devcentral
@devcentral 6 жыл бұрын
Hi Abhay, great question! A filter for the client side wouldn't work for this because there's no way to reach out and configure every possible client that might attack you in this situation. Specifically for the Mirai botnet, many of the clients would be things like a DVR, wireless camera, etc. These are many of the "Internet of Things (IoT)" devices that have been taken over by the Mirai botnet. So, while these internet-connected devices can send DNS requests on behalf of the botnet, it would be basically impossible to reach out and try to put a filter on each of them. This is why it's important to implement a firewall (like the BIG-IP AFM) to filter out these malicious requests. I hope this helps!
@serkantok5195
@serkantok5195 5 жыл бұрын
great explanation btw. thanks..
@devcentral
@devcentral 5 жыл бұрын
glad you enjoyed it!
@msa6467
@msa6467 6 жыл бұрын
Good explanation
@devcentral
@devcentral 6 жыл бұрын
glad you enjoyed it!
Real Attack Stories: A Flood of DDoS
16:20
F5 DevCentral
Рет қаралды 9 М.
What is DDoS?
9:57
F5 DevCentral
Рет қаралды 49 М.
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 55 МЛН
What is DNS (Domain Name System)?
7:25
IBM Technology
Рет қаралды 146 М.
Explaining TLS 1.3
18:00
F5 DevCentral
Рет қаралды 74 М.
The Attack That Could Disrupt The Whole Internet - Computerphile
9:50
Computerphile
Рет қаралды 1,5 МЛН
What is a Web Application Firewall (WAF)?
10:04
F5 DevCentral
Рет қаралды 256 М.
HTTP2
13:45
F5 DevCentral
Рет қаралды 21 М.
DNS Reflection Attack Explained
7:43
Hussein Nasser
Рет қаралды 14 М.
What is a TLS Cipher Suite?
20:47
F5 DevCentral
Рет қаралды 117 М.
Perfect Forward Secrecy
13:26
F5 DevCentral
Рет қаралды 73 М.
What Hacking the Planet Taught Us About Defending Supply Chain Attacks
30:36
SANS Offensive Operations
Рет қаралды 212
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 55 МЛН