Domainsite.com DNS Security Breached by DDoS Attack

Three out of Four DNS Servers Overloaded by DDoS-Generated Traffic

September 5, 2007 - Domainsite.com was a large company selling domain names. At the start of September 2007, they came up with an offer for free .info domain names. However, a carefully planned Distributed Denial of Service (DDoS) attack targeted the website and caused irreversible damage.

At the start of the DDoS attack, IT thought the latency was due to increased Domain Name Service (DNS) server traffic caused by too many people registering the free .info domains. Later, Domainsite.com realized that their DNS was being hit by a DDoS attack. In the middle of the night, the DDoS attack disrupted DNS services for many of the company's clients due to the overload of the DNS servers. Many clients started complaining that their domains were inaccessible. Domainsite.com did not know if the DDoS attack was related to the .info traffic.

The company had four DNS servers and three of the DNS servers were at the same location. The three clustered DNS servers were attacked which caused all the down time. The CEO of Domainsite.com was at the datacenter a whole day trying to stop the DDoS attack.

Eventually the traffic flooding the three DNS servers was exceeding the company's bandwidth. To counterattack, experts were brought in to isolate the targeted DNS servers on another part of the network. The DDoS attack lasted for almost 24 hours, causing Domainsite.com services to be disrupted. The free .info domains attracted too much attention, and from the wrong people.

Source: DNForum.com

About Secure64 Software Corporation
Secure64® is a software developer providing highly secure DNS and server applications with built-in denial-of-service protection features to help ensure your Internet-dependent business is always accessible. Based on the genuinely secure SourceT® microOS, Secure64 DNS remains highly available during network attacks and is immune to compromise from rootkits and malware.