Dnspod Station long talk about large-scale failure: 100,000 domain name is inaccessible

Source: Internet
Author: User
Keywords Server domain name resolution dnspod Wu Hongshong
Dnspod webmaster Wu Hongshong received Sina Science and technology interview May 21 evening, leading to a number of provincial network fault reason chain source, free domain Name Service provider dnspod Webmaster Wu Hongshong first appeared today to accept Sina Science and technology interview, because Dnspod encounter malicious attack finally led to a number of provincial network breakdown paralysis event to explain.  Wu Hongshong that Dnspod was also the victim. Wu Hongshong revealed that the Dnspod server on the domain name of about 100,000, the server 18th night in total about 10G traffic attacks, resulting in 100,000 domain names inaccessible, including Storm audio and video.  As the storm audio and video has a huge user, after the Dnspod protocol buffer time, 19th night to the Internet terminal frequently launched Domain name resolution request, resulting in network failure. Wu Hongshong that DNS as one of the most basic services, the attention is very small, based on the prevention of DNS is weak, hackers will seize this weak link to attack DNS. He also said that there is no user compensation, many users to his message to express support and encouragement.  He also hopes that members will pay more attention to the weak links of internet security. The following is an interview record: Dnspod is also the victim Sina Science and technology Han Ji: Everyone sina netizen good evening, welcome to Sina chat Room. May 19 Evening Many provincial network failures attract attention.  Today we are invited to one of the event focus, free domain name resolution Service Site Dnspod webmaster Wu Hongshong with us to talk about this situation, first of all, please Wu Hongshong with our friends to say hello.  Wu Hongshong: Everybody good friends.  Sina Science and technology: perhaps Netizen is not very familiar to dnspod, can introduce the main business of the website first, and dnspod in this accident play role. Wu Hongshong: This incident dnspod also one of the victims. First of all, I would like to introduce dnspod, we all know that the domestic division of Telecommunications and Netcom, telecommunications and Netcom exchange is very slow, dnspod mainly for everyone to solve a problem? Before we open a website will find that there is a telecommunications portal from this entry or Netcom users from this entry.  With Dnspod, the user does not have to choose any more, and it directly picks up the nearest server for the user.  Sina Science and Technology: Dnspod is a website that provides the free service, what currently service is bigger website have?  Wu Hongshong: Domestic including storm audio and video, VERYCD, rain forest Wind, 4399, games and other sites are using our dnspod services. Sina Technology: The Ministry of Industry later issued a bulletin to inform the situation, because the storm audio and video domain name providers have been attacked on a large scale, resulting in a number of provincial failures.  Inside said the domain Name service provider that is the dnspod, can introduce the story. Wu Hongshong: May 18 Night 9 o'clock more, someone and I said dnspod problems, can not visit.  The specific reason is that the server was attacked. Sina technology: This is theThe first attack of the incident, right?  Wu Hongshong: At that time I was outside, received a friend of the phone said the server was attacked, and then went up to find the server was nearly a heavy flow of more than g, then found that the server was forcibly off the shelf.  Attack total traffic reached 10 g Sina Technology: This attack traffic there is no a ballpark figure?  Wu Hongshong: At the beginning of that attack traffic is a multiple G attack on each server, because each place has a server, the last attack amount of about 10 g or so.  Sina Science and Technology: is not 18th night that one day in Changzhou, Jiangsu, the main server has been sealed off?  Wu Hongshong: Yes.  Sina Science and Technology: where Dnspod all have server?  Wu Hongshong: dnspod main server in Changzhou, in addition, in Guangxi, Tianjin have servers.  Sina Technology: Now we are pointing to the storm audio and video, the final contradiction in the Storm audio and video here broke out.  Wu Hongshong: This is caused by the storm audio and video software mechanism, in fact, no matter what software is changed, this problem may occur. Sina technology: I see some people on the internet say this is a malicious attack, this How do you think?  It is said that a malicious attack, there is no investigation of the attack from where?  Report to the Public Security Bureau to investigate the matter Wu Hongshong: not at present, but we have reported to the Public Security Bureau to investigate this matter.  Sina Science and technology: I actually saw we also wrote a user apology letter in the evening of 19th, at that time wrote this letter is what consideration?  Wu Hongshong: This is a kind of responsibility to the user, because the appearance of this situation is everyone do not want to see, the user also has the right to know, so I wrote that letter of apology. Sina Science and technology: actually just say your website, your server is attacked, why then turn into the national many provinces to appear so thing? What kind of thing is in between?  Because you said before that this is a butterfly effect, can you explain? Wu Hongshong: Because at first there was a hacker attack Dnspod,dnspod as the victim could not continue to provide services. Just the storm. Audio and video use Dnspod to resolve domain names. 18th night The storm is not a problem, because the Dnspod agreement has a buffer time, the next night, that is, May 19 night 9 o'clock, just storm audio and video This domain name of the cache in all parts of the Dnspod server, also shows that the Storm audio and video of the installed capacity is very large,  The software does not request a domain name, and constantly to the local dnspod to launch a request, which may create a disguised form of a large number of visits, and finally caused the network paralysis telecommunications congestion.  Sina Technology: The logic of this thing can not be understood as, you have been attacked, telecom sealed off one of your servers, and this server is your primary server, which led to all users they are unable to access, including the Storm audio and video, and ultimately caused by the province of the paralysis, is this the thing?  Wu Hongshong: Yes. Sina Science and Technology: Do you know that there was a massive network malfunction at number 19th?  Wu Hongshong: Because I've been dealing with Dnspod's attacks, I also found a lot of users reporting it to me on the internet on the evening of May 19, but it didn't occur to me that we were being attacked.  Sina technology: How do you know later?  Wu Hongshong: Later the next day when I saw the news, I found that the problem was somewhat related to my side.  Sina Technology: Because the Ministry of Industry attaches great importance to this matter, there are no related enterprises these people to find you? Wu Hongshong: Then the storm audio and video over there to contact me, the matter we have met, together to understand this matter. [Page] Dnspod have the opinion "/> dnspod webmaster Wu Hongshong Accept Sina Science and technology interview a small number of users of the attack on the issue of Sina Technology: Now how the user response?  Because we may feel that this time probably stopped 2, 3 hours, the loss to the user, may also have a lot of your site also caused the loss, their attitude now?  Wu Hongshong: At present, most users still support us, but because of the impact is relatively large, there are a small number of users on our matter have a little opinion.  Sina technology: Do you feel the pressure is big now?  Wu Hongshong: There's still a lot of pressure.  Worry about the loss of user claims Sina technology: What are your concerns and concerns? Wu Hongshong: Because of such things, including the Ministry of Industry, they are very attached importance, do not know whether the Ministry has related policies, or to this sector caused some other impact or something.  In addition, some users may cause losses and will seek compensation.  Sina Technology: I understand this website only you are doing?  Wu Hongshong: Yes, I am doing this site alone.  Sina technology: But in fact, you do not small, because you for a lot of sites to provide domain name resolution services, can you disclose how much you are commonly used domain name? Wu Hongshong: At present we register user more than 130,000, add user more than 600,000, but actually in use those domain name, the domain name that normally resolves nearly 100,000.  Our request is nearly 2 billion.  Sina Technology: The day of the accident is not equivalent to 100,000 domain names have no way to visit?  Wu Hongshong: Yes.  Sina Technology: Is it because of the impact of the storm is relatively large, we have focused on this side of the focus?  Wu Hongshong: Because of this thing, the storm is affected relatively big, everybody also is very concerned about the storm this software.  Sina technology: How many servers does the website have at ordinary times? Wu Hongshong: There are 6 servers for the average user, 4 servers for those more important customers.  In addition, I have a number of databases here, as well as the Web site, altogether add up to 16 units. Sina technology: So many servers are required to invest in cost and manpower to maintain. You just said that your site isFree, how did the money come from?  Wu Hongshong: In fact dnspod itself is to solve the needs of everyone to build, now all the servers are actually dnspod those users provide free.  Sina Technology: The equivalent of their time to provide a server, let you help them do this service, right?  Wu Hongshong: It's like I'm offering them a technique to help them get things done.  Sina technology: About you personally, I have heard that you are part-time to do this thing, before the main where to work?  Wu Hongshong: Previously in a number of network companies, has now come out, originally in MySpace. Sina technology: Now you are thinking of personal entrepreneurship?  Is it considered that there are some charges on this site?  Wu Hongshong: Because a lot of users are asking us to provide a paid service, I'm thinking about opening up this business. Sina technology: In fact, now we this domain name resolution service industry is what kind of situation?  Are there many competitors?  Wu Hongshong: At present, there are about 10 dozen in the country to do smart DNS, which has free, there are charges, but the biggest is what I do dnspod.  Sina Science and Technology: you belong to personal interest hobby has been doing this thing?  Wu Hongshong: Yes, I've been doing it because of my personal interests.  This attack is an inevitable event Sina technology: After this thing comes out, do you think this is an accidental event, or develop to a certain degree of an inevitable event?  Wu Hongshong: I think it is an inevitable thing, whether now or in the future, it will certainly produce such a thing.  Sina technology: I have heard that the first hacker is to attack the Web server, then found no way to attack, and then attack the Dnspod server, is it because we domestic DNS this piece or not enough attention?  Wu Hongshong: DNS as a basic service, not yet how many people are familiar with, we can say that the focus on it is basically not.  Sina Technology: We have also been attacked before, has it been so large?  Wu Hongshong: Dnspod is also subject to a number of large and small attacks, the largest attack on the flow of nearly 24 g.  Sina Science and Technology: Have you analyzed the attack before? Wu Hongshong: All are malicious attacks between websites to retaliate.  Because now everyone knows the web-based attack, the preventive measures are relatively perfect, but the security based on DNS is very weak, hackers will seize this weak link to the DNS attack.  Sina Technology: Some of the Web sites before the attack on our servers, this time is not related to them, now there are no signs of this?  Wu Hongshong: Not yet, only to say suspicion.  Sina technology: Is the next step is to report to the police?  Wu Hongshong: Yes, now they are communicating with the Ministry of Communications, this incident. Sina Science and technology: hurriedly go to report, give user an account to?  Do you have a claim from a user now?  Wu Hongshong: Not at the moment.  Sina Technology: What is the attitude of users to you at present?  Wu Hongshong: Now many users on the QQ message to me, are very supportive I continue to do this thing, let me very moved.  Sina Science and technology: Before being attacked, did you report a case?  Wu Hongshong: Not before.  Sina technology: Why?  Wu Hongshong: Because there is no way to find out where to report, because to play 110 of what the basic will not accept such a situation.  Sina technology: For example, your main server in Changzhou, if the main server is broken must fly to the side of the report.  Wu Hongshong: Generally in the location of your business to report, but because now dnspod is entirely an individual in operation, no company in operation, so there is no way to report.  Sina technology: In fact, sometimes you have a problem very want to report, but found a little find the feeling of the road.  Wu Hongshong: Yes, very confused.  Sina Technology: I believe this incident is also let you feel very deep, because we have limited time, there are a lot of netizens are concerned about this thing, but also in the development of the site, what words want to say to them?  Wu Hongshong: I hope that we can pay more attention to the weak security links on the Internet, and hope that we continue to support dnspod, thank you. Sina technology: Thank you.
Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.