Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: [1] 2

Author Topic: Google DNS broken?  (Read 3721 times)

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Google DNS broken?
« on: October 21, 2016, 07:12:15 PM »

Ive been attempting to get to paypal to pay a bill, but their website wouldnt load as server not found for the past few hours.
Then I noticed various other large US based sites were also unobtainable. ie twitter

downforeveryoneorjustme was exceedingly slow to load for some reason.   But when it eventually did load it said "paypal.com' is up.
Yet isitdownrightnow says 'paypal is down for everyone'.

Tracerts showed what looks like could be a dns issue.

Code: [Select]
C:\WINDOWS\system32>tracert www.paypal.com
Unable to resolve target system name www.paypal.com.

C:\WINDOWS\system32>tracert twitter.com
Unable to resolve target system name twitter.com.

Changed my dns settings from google to OpenDNS [208.67.220.220/2-8.67.222.222] and the internet sprang back to life.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

jelv

  • Helpful
  • Kitizen
  • *
  • Posts: 2054
Re: Google DNS broken?
« Reply #1 on: October 21, 2016, 07:28:12 PM »

I've seen something that suggests there is a big DDOS going on.
Logged
Broadband and Line rental: Zen Unlimited Fibre 2, Mobile: Vodaphone
Router: Fritz!Box 7530

jelv

  • Helpful
  • Kitizen
  • *
  • Posts: 2054
Re: Google DNS broken?
« Reply #2 on: October 21, 2016, 07:29:03 PM »

Just found this: http://www.bbc.co.uk/news/technology-37728015

PayPal is specifically mentioned.
Logged
Broadband and Line rental: Zen Unlimited Fibre 2, Mobile: Vodaphone
Router: Fritz!Box 7530

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Google DNS broken?
« Reply #3 on: October 21, 2016, 07:40:06 PM »

Thanks.   Wonder if they are also attacking googles DNS servers.   
Its strange that I couldnt reach many sites when using google's DNS servers, but now Im using OpenDNS everything seems ok.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

NEXUS2345

  • Reg Member
  • ***
  • Posts: 235
Re: Google DNS broken?
« Reply #4 on: October 21, 2016, 07:42:52 PM »

Yeah, a managed DNS provider called Dyn have been experiencing a DDoS attack, which is grinding many websites to a halt. Twitter, Github, PayPal, Ebay, and many others.

http://www.theregister.co.uk/2016/10/21/dns_dyn_ddos/

https://www.dynstatus.com/

OpenDNS might simply have not cleared their cache yet, or may be sourcing it from a different DNS zone.

There is mention of an escalated attack, but not sure what they meant by this. Could be that they are targeting multiple DNS providers, although Google would be very difficult a target to take down with just a DDoS.
Logged
Security improvement and remediation consultant with infrastructure specialisation

IDNet Openreach FTTP 1000/115 + Asus RT-AX92U | Virgin Media 200 + SuperHub 3 + Synology MR2200ac mesh | Sky 80/20 with WiFi Guarantee on Huawei 288 cabinet

Bowdon

  • Content Team
  • Kitizen
  • *
  • Posts: 2395
Re: Google DNS broken?
« Reply #5 on: October 21, 2016, 08:03:35 PM »

I noticed the story in the newspaper this morning and it wasn't effecting UK people. But now it is. PSN is down too. Paypal is listed as well.

I'm getting DNS error and I moved away from Google DNS a few days ago. So its not only Google's DNS.

Hopefully things settle soon.
Logged
BT Full Fibre 500 - Smart Hub 2

Bowdon

  • Content Team
  • Kitizen
  • *
  • Posts: 2395
Re: Google DNS broken?
« Reply #6 on: October 21, 2016, 08:05:42 PM »

http://gizmodo.com/this-is-probably-why-half-the-internet-shut-down-today-1788062835

Quote
Twitter, Spotify and Reddit, and a huge swath of other websites were down or screwed up this morning. This was happening as hackers unleashed a large distributed denial of service (DDoS) attack on the servers of Dyn, a major DNS host. It’s probably safe to assume that the two situations are related.

Update 12:28 PM EST: Dyn says it is investigating yet another attack, causing the same massive outages experienced this morning. Based on emails from Gizmodo readers, this new wave of attacks seems to be affecting the West Coast of the United States and Europe. It’s so far unclear how the two attacks are related, but the outages are very similar.
Logged
BT Full Fibre 500 - Smart Hub 2

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Google DNS broken?
« Reply #7 on: October 21, 2016, 08:29:18 PM »

Just seen this which may in part explain why OpenDNS is working?

Quote
Out of curiosity, why do caching DNS resolvers, such as the DNS resolver I run on my home network, not provide an option to retain last-known-good resolutions beyond the authority-provided time to live? In such a configuration, after the TTL expiration, the resolver would attempt to refresh from the authority/upstream provider, but if that attempt fails, the response would be a more graceful failure of returning a last-known-good resolution (perhaps with a flag).

Quote
>>  OpenDNS does this: It's called SmartCache.

>>> Anyone know if Google Public DNS does?

>>>> It doesn't (first result is openDNS, second is google):


Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

jid

  • Content Team
  • Kitizen
  • *
  • Posts: 1945
Re: Google DNS broken?
« Reply #8 on: October 21, 2016, 08:44:17 PM »

Yep OpenDNS do some local caching their end, I realised what was going on when I saw the news article on BBC and added secondary DNS as OpenDNS and thats resolving the addresses - Google's DNS is still failing.
Logged
Kind Regards
Jamie

BT FTTP - 75meg | Sky Q |  Bridgend Weather

Starman

  • Reg Member
  • ***
  • Posts: 223
Re: Google DNS broken?
« Reply #9 on: October 21, 2016, 09:06:57 PM »

Yeah that would explain issues this evening so I added OpenDNS has my secondary server so at least one provider should remain online.
« Last Edit: October 22, 2016, 06:13:45 AM by Starman »
Logged

NEXUS2345

  • Reg Member
  • ***
  • Posts: 235
Re: Google DNS broken?
« Reply #10 on: October 21, 2016, 09:28:48 PM »

This is an analysis from Brian Krebs, whose site along with OVH were subject to the largest DDoS attacks ever seen (620Gbps and 1.2Tbps respectively).

https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/
« Last Edit: October 21, 2016, 09:37:50 PM by NEXUS2345 »
Logged
Security improvement and remediation consultant with infrastructure specialisation

IDNet Openreach FTTP 1000/115 + Asus RT-AX92U | Virgin Media 200 + SuperHub 3 + Synology MR2200ac mesh | Sky 80/20 with WiFi Guarantee on Huawei 288 cabinet

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Google DNS broken?
« Reply #11 on: October 21, 2016, 09:55:24 PM »

Article in elreg - link

Quote
After two hours into the initial tidal wave of junk traffic, Dyn announced it had mitigated the assault and service was returning to normal. But the relief was short lived: just about an hour later, the attack resumed

/snip/

OpenDNS is about the only major public DNS provider weathering the storm – if you're having problems connecting to websites, you should use OpenDNS's resolvers at 208.67.222.222 and 208.67.220.220. OpenDNS uses smart caching during outages to keep looking up hostnames even if the websites' backend DNS is flooded off the 'net.

I hadn't seen other articles, I'd tried to pay for something quickly by paypal, but then had to go out, so didnt really have time to look.   When I got back it was then I realised it was also affecting some other websites too, and from a tracert it looked like it could be DNS.   I just happened to pick OpenDNS because it was the other public DNS that I knew off the top of my head. 

Good way to take out the internet - knock out all the major DNS servers :(
In the meantime speculation begins as to who the culprit is and their motive.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7409
  • VM Gig1 - AAISP CF
Re: Google DNS broken?
« Reply #12 on: October 21, 2016, 10:01:50 PM »

These companies have made themselves extra vulnerable by the fact they all have very low TTL A records, so dns lookups wont be cached for long.
Logged

NEXUS2345

  • Reg Member
  • ***
  • Posts: 235
Re: Google DNS broken?
« Reply #13 on: October 21, 2016, 10:24:39 PM »

These companies have made themselves extra vulnerable by the fact they all have very low TTL A records, so dns lookups wont be cached for long.

While this could be seen as a vulnerability, it is also an advantage, because as GitHub have done, it aids in the transition to a new provider in lieu of their current provider being attacked.

In terms of this attack, the fallout initially will last a few days I feel, but we will probably see in the long term a lot of companies moving to in house DNS, or moving to providers that actually use DDoS protection in front of their servers that are capable of defeating such large attacks.
Logged
Security improvement and remediation consultant with infrastructure specialisation

IDNet Openreach FTTP 1000/115 + Asus RT-AX92U | Virgin Media 200 + SuperHub 3 + Synology MR2200ac mesh | Sky 80/20 with WiFi Guarantee on Huawei 288 cabinet

Dray

  • Kitizen
  • ****
  • Posts: 2361
Re: Google DNS broken?
« Reply #14 on: October 21, 2016, 10:44:59 PM »

Are you aware that Dyn DNS are currently suffering a Ddos attack?
https://www.wired.com/2016/10/internet-outage-ddos-dns-dyn/
Logged
Pages: [1] 2
 

anything