On December 10, 2014, starting at noon I suddenly found web pages slow to open or even failing to open, with domain resolution failures. The cause is now clear: recursive DNS servers in multiple provinces were hit by a DDoS attack, affecting the national network.
This afternoon, some users reported abnormal DNS resolution. After ruling out DNS faults and verifying with operators, it was confirmed that recursive DNS resolution anomalies currently exist. @DNSPod’s official Weibo said that operators across the entire network are currently suffering reflection attacks from a botnet, causing a drop in DNS resolution success rates for all users.
It is understood that this nationwide DNS instability began around 10 a.m., expanded around 12 noon, and is still ongoing. Currently, some operators have contacted the provincial internet emergency response centers to handle the matter. But who controls the botnet that launched the attack remains unanswered.
Explainer: DNS recursive query: Generally, the relationship between a client and a server is recursive — when a client sends a request to a DNS server, if the DNS server itself cannot resolve it, it sends a query request to another DNS server and forwards the result to the client. There is also the iterative query (repeated query), which is between DNS servers. DDoS: Distributed Denial of Service attack, also called a server-blocking attack, which uses client/server technology to combine multiple computers as an attack platform to launch attacks against one or more targets, multiplying the attack’s power.
