Re: [Pdns-users] TCP amplification attack notes

2019-08-18 Thread Brian Candler
On 18/08/2019 15:34, Mike wrote: I think the point here is that even with, you would still be transmitting the SYN-ACK regardless. Yes, but only once (so little or no amplification) ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://

Re: [Pdns-users] TCP amplification attack notes

2019-08-18 Thread Mike
On 8/18/19 2:59 AM, Brian Candler wrote: > On 18/08/2019 04:14, Mike wrote: >> I wanted to point out that I observed the same thing occuring >> against my PowerDNS resolvers - I would get a low rate of TCP SYN's in >> to port 53, the resolver would attempt to SYN-ACK these several times >> wit

Re: [Pdns-users] TCP amplification attack notes

2019-08-18 Thread Brian Candler
On 18/08/2019 04:14, Mike wrote:     I wanted to point out that I observed the same thing occuring against my PowerDNS resolvers - I would get a low rate of TCP SYN's in to port 53, the resolver would attempt to SYN-ACK these several times without success, and then a new SYN would come in, start