“Shit, Helen, we’re all disposable. You’re disposable, too... That’s how this works. Same with me. We all have to find ways to keep ourselves indispensable, for the time being.” apple.news/AT8w_wN5hSzOS65Kg…
Reason number eleventy-billion to be using “allow-recursion” ACLs on your internet-facing BIND DNS servers, along with rate-limit. But, yes, please patch.
FYI: A vulnerability was found in the domain name system that can be exploited to massively amplify traffic to a victim's DNS server, knocking it offline
You need to patch at least:
ISC BIND, NLnet labs Unbound, PowerDNS, and CZ NIC Knot Resolver
theregister.co.uk/2020/05/21…
We all need to work together. Any weakness is a weakness that needs to be fixed, let's work together to fix things.
As I said, things are only fragile till they break.
Or, as @k8em0 says "Don't hate the researcher, hate the vuln."
This morning’s Florida wildlife adventure was rescuing the 5lb turtle from my pool and releasing it in the neighborhood retaining pond. Poor little lost dinosaur.