At around 10:00am EST +/- 5 mins both ns1 and ns2 received sharp spikes of inbound traffic lasting approximately 15 minutes. While the volume of those spikes was not overpowering, the servers did timeout some queries.
As many people know, we have been under DDoS attack against ns1 and ns2 since last week. The attack has been ongoing but mitigated since last friday.
We are operating on the theory that this morning’s spike is another wave in the DDoS and we are currently analyzing the attack traffic.
At the moment, all systems have resumed normal functioning.
Was one of the first calls on this in am. Resolution failure on 3 of my domains (all 3 look to ns1 and ns2) appears to be ok after 12 noon ET. However, now 625 pm ET and problem just started again. I have asked my clients to change these pointers to new system but no response yet. Why is this still happening? Domains effected are smf-cpa.com, njpies.org, franciseparker.com.
As noted, we have found that it’s likely to be a client, though we can’t name names, but the attacks are not against our new clusters, so we are urging folks to migrate. For the time being, as you know, the attacks have abated.
Enter your email below to receive a concise, insightful weekly briefing and stay informed about cyberthreats and relevant tech happenings.
For the time being you do not have to be an easyDNS member to receive #AxisOfEasy, however when you subscribe we'll send you a $10 coupon in case you ever decide to try out one of our many web services.
Get on the #AxisOfEasy List
AxisOfEasy Weekly
Enter your email below to receive a concise, insightful weekly briefing and stay informed about cyberthreats and relevant tech happenings.
For the time being you do not have to be an easyDNS member to receive #AxisOfEasy, however when you subscribe we'll send you a $10 coupon in case you ever decide to try out one of our many web services.
Was one of the first calls on this in am. Resolution failure on 3 of my domains (all 3 look to ns1 and ns2) appears to be ok after 12 noon ET. However, now 625 pm ET and problem just started again. I have asked my clients to change these pointers to new system but no response yet. Why is this still happening? Domains effected are smf-cpa.com, njpies.org, franciseparker.com.
MWN
Hi there,
As noted, we have found that it’s likely to be a client, though we can’t name names, but the attacks are not against our new clusters, so we are urging folks to migrate. For the time being, as you know, the attacks have abated.