Vox - Sudden Increase in Traffic (DNS Amplification Attack)

morkhans

A MyBroadband
Super Moderator
Joined
Jun 22, 2007
Messages
10,897
Reaction score
474
Location
Cape Town
Can't decide between security and ISP section, might get more exposure here.

I've now seen two separate instances in the last week where Vox customers (specifically Capped Business Fibre) noted an alarming increase in daily traffic (bulk of it was upload).

Clients could not see any traffic passing through their firewall. After turning off the firewall the traffic continued. This finally convinced Vox to investigate. While waiting for feedback I happened to run a scan against the router and found that DNS was open. After Vox locked things down the traffic disappeared.

In both cases onsite router was a Mikrotik. No issue there, just poorly configured.

I imagine this could be affecting uncapped customers as well, but perhaps they won't notice unless the DNS abuse starts affecting the performance of their link.

You can read more about how this works here: https://mikrotiknetworking.wordpress.com/2016/03/18/dns-amplification-attack/
 
Last edited:
A month or two ago, while I was away and all my computers were switched off, I had a 100GB upload showing on Vox in one day.

I phoned them, they couldn't explain it.

I assumed that someone had uploaded 100GB of junk video footage from my DVR (security cameras), I couldn't explain it.

BTW, I have an Asus router.
 
Good point (OP updated): DNS amplification will show up mostly as upload traffic.

Assuming the Asus router is your own equipment, you would be liable to secure it. In this case Vox has supplied and configured the router, so only they have access to it.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X