Tuesday, March 3, 2026
[Incident Report #028][DNS] Name Server Attack
Update:
AS20473 is still attempting to throw a large amount of traffic at
our name servers, but our drop rules are in place and appear to
be working as intended.
What Happened?
From around 0600 to 0730EST this morning, our name servers
were hit with a large amount of traffic originating from a data center
in the Netherlands under AS20473. The traffic was spread across
multiple IPv6 subnets and volume was high enough the it saturated
the virtual bridges that our name servers are operating behind. This
is the fourth attack of this kind that our network seen in the past
two weeks.
Upon looking at the traffic reaching the name servers, it appears that
a handful of IPs originating from AS20473 are performing scattered
shot lookups for all kinds of domain NS records with no rhyme or
reason to the data they are requesting and they are doing so at a
rate that is affecting the usability of our network rate limited services.
What damages Resulted?
During the attack, we saw the following issues:
- Accounting service lost contact with NS2
- Legitimate name lookups were being dropped or timed out
- The NMS lost SNMP contact with NS1 and NS2 momentarily
- High CPU load on Nardoragon router
What are we doing to deal with this?
As a result of repeated abuse from this provider, we have:
- Applied drop rules at edge router for Phy One, dropping AS20473
- Applied drop rules at edge router for Phy Two, dropping AS20473
The FurrIX vIX will not tolerate abuse of our services to the point in
which it affects our operations internally or causes issues for members
of our exchange and going forward, we will be quicker to start dropping
abusive traffic all together.
Tuesday, February 24, 2026
Control of the LIR Subnets Assumed
As of this morning, FurrIX has assumed control of what was MFN’s
subnets. WHOIS and operational information has been updated, but
name server zones for PTR will have to be updated as time permits.
We are also in the process of redoing our agreement with MFN to
ensure that they can transition to a nested environment and stay
operational as a community web and game server host.
As part of the network changeovers, FurrIX is looking to renumber
and reconfigure the network as well as creating full documentation
of how each router, subnet and member connection is configured and
maintained.
We will release more information as plans finalize.
Updating Records
Half awake in the NOC because I can’t sleep, so I’m taking some
time this morning to work on some of our networking records and
to bring the zone files for FurrIX up to date.
Shouldn’t affect anything in our routing gear.
- Adrian
Sunday, February 22, 2026
Releasing Domains and Ongoing Amplification Attacks
FurrIX has chosen not to renew the domains ‘birb.rest’ and ‘avali.rest’ for cost reasons.
These domains are not a core part of our network stack and were only used for personal
splash pages and a handful of user subdomains that have not seen lookups in some time.
This should not affect our operations, or that our members, in any meaningful way.
We are also dealing with a DNS amplification attack that is abusing ANY queries and will be
temporarily dropping any IP address that cross over 40 request per second until the incoming
traffic targeting the domains starts to ease up. This has been going on for several hours and
we are working to limit the amount of traffic crossing or originating from our network.
Sunday, February 8, 2026
Getting Ready to Take Over Name Servers
The FurrIX NOC is getting ready to take our the name servers from
Marbled Fennec Networks. This move will place the name servers
into FurrIX control and add them into our workflow directly instead
of having to go through MFN for changes and updates.