{"id":3525,"date":"2026-03-31T09:19:07","date_gmt":"2026-03-31T07:19:07","guid":{"rendered":"https:\/\/vasil.ludost.net\/blog\/?p=3525"},"modified":"2026-03-31T09:19:36","modified_gmt":"2026-03-31T07:19:36","slug":"2026-03-31-dns-ddos","status":"publish","type":"post","link":"https:\/\/vasil.ludost.net\/blog\/?p=3525","title":{"rendered":"2026-03-31 DNS DDoS"},"content":{"rendered":"<p>\u041d\u043e\u0440\u043c\u0430\u043b\u043d\u0438\u0442\u0435 \u0445\u043e\u0440\u0430 \u0441\u0435 \u0431\u0443\u0434\u044f\u0442 \u0441 \u043a\u0430\u0444\u0435, \u0430\u0437 &#8211; \u0441 DDoS.<\/p>\n<p><a href=\"https:\/\/vasil.ludost.net\/pics\/20260331iptables_dns.png\">\u0413\u0440\u0430\u0444\u0438\u043a\u0430 \u043d\u0430 DNS \u0442\u0440\u0430\u0444\u0438\u043a\u0430<\/a>.<\/p>\n<p>\u041d\u0430\u043a\u0440\u0430\u0442\u043a\u043e, \u043e\u0442 \u0432\u0447\u0435\u0440\u0430 \u043d\u044f\u043a\u0430\u043a\u0432\u0438 \u0445\u043e\u0440\u0430 DDoS-\u0432\u0430\u0442 DNS \u0441\u044a\u0440\u0432\u044a\u0440\u0438, \u043f\u043e TCP, \u0441 \u043e\u043f\u0438\u0442 \u0437\u0430 \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u0432\u043d\u0438 resolve-\u0432\u0430\u043d\u0438\u044f, \u043a\u0430\u0442\u043e \u043d\u0435 \u0437\u0430\u0442\u0432\u0430\u0440\u044f\u0442 \u0432\u0440\u044a\u0437\u043a\u0438\u0442\u0435, \u0438 \u0432 \u0435\u0434\u0438\u043d \u043c\u043e\u043c\u0435\u043d\u0442 \u0441\u0432\u044a\u0440\u0448\u0432\u0430 \u043e\u043f\u0430\u0448\u043a\u0430\u0442\u0430 \u043d\u0430 \u0441\u044a\u0440\u0432\u044a\u0440\u0430. \u0412 \u043b\u043e\u0433\u043e\u0432\u0435\u0442\u0435 \u0441\u0438 \u043b\u0438\u0447\u0438 \u043f\u043e<\/p>\n<pre>\nMar 31 10:16:48 marla named[221347]: client @0x7f2263433c98 177.54.96.29#40555 (arvika.se): query failed (REFUSED) for arvika.se\/IN\/TXT at query.c:5703\nMar 31 10:16:48 marla named[221347]: client @0x7f226e79a498 177.223.238.74#43398 (ns3.aixzellent.com): query failed (REFUSED) for ns3.aixzellent.com\/IN\/AAAA at query.c:5703\nMar 31 10:16:52 marla named[221347]: client @0x7f225e7d5c98 177.54.96.29#41861 (DAN.Net.uk): query failed (REFUSED) for DAN.Net.uk\/IN\/ANY at query.c:5703\nMar 31 10:16:54 marla named[221347]: client @0x7f226f595498 177.54.96.29#42734 (shop-goudwisselkantoor.nl): query failed (REFUSED) for shop-goudwisselkantoor.nl\/IN\/ANY at query.c:5703\n<\/pre>\n<p>\u0422\u0435\u043a\u0443\u0449\u043e\u0442\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u043d\u043e \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0435 \u0432 server \u0441\u0435\u043a\u0446\u0438\u044f\u0442\u0430 \u0434\u0430 \u0441\u0435 \u0434\u043e\u0431\u0430\u0432\u0438:<\/p>\n<pre>\n        tcp-clients 10000;\n        tcp-initial-timeout 100;\n        tcp-idle-timeout 100;\n        tcp-keepalive-timeout 50;\n        tcp-advertised-timeout 0;\n<\/pre>\n<p>\u0422\u043e\u0432\u0430 \u043d\u0430\u043a\u0440\u0430\u0442\u043a\u043e \u0432\u0434\u0438\u0433\u0430 \u043a\u043e\u043b\u043a\u043e \u043c\u043e\u0436\u0435 \u0434\u0430 \u0441\u0430 \u043f\u0430\u0440\u0430\u043b\u0435\u043b\u043d\u0438\u0442\u0435 \u0432\u0440\u044a\u0437\u043a\u0438, \u0441\u043c\u044a\u043a\u0432\u0430 idle\/keepalive timeout-\u0438\u0442\u0435, \u0442\u0430\u043a\u0430 \u0447\u0435 \u0434\u0430 \u043d\u0435 \u043c\u043e\u0436\u0435 \u0434\u0430 \u0432\u0438\u0441\u0438 \u043d\u044f\u043a\u043e\u0439 30 \u0441\u0435\u043a\u0443\u043d\u0434\u0438, \u0438 \u0432 \u043e\u0442\u0433\u043e\u0432\u043e\u0440\u0438\u0442\u0435 \u043a\u0430\u0437\u0432\u0430, \u0447\u0435 \u043d\u0435 \u043f\u043e\u0434\u0434\u044a\u0440\u0436\u0430 keepalive (\u0442.\u0435. \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0434\u0430 \u0441\u0438 \u0434\u044a\u0440\u0436\u0438 \u0432\u0440\u044a\u0437\u043a\u0430\u0442\u0430 \u043e\u0442\u0432\u043e\u0440\u0435\u043d\u0430 \u0437\u0430 \u043e\u0449\u0435 \u043d\u044f\u043a\u0430\u043a\u0432\u0438 \u0432\u044a\u043f\u0440\u043e\u0441\u0438). \u0418\u0437\u0433\u043b\u0435\u0436\u0434\u0430 \u0434\u0430 \u043a\u0440\u0435\u043f\u0438 \u043d\u0430 \u043e\u043a\u043e\u043b\u043e 2000-3000 \u043e\u0442\u0432\u043e\u0440\u0435\u043d\u0438\u0442\u0435 \u0432\u0440\u044a\u0437\u043a\u0438 \u0432 \u043c\u043e\u043c\u0435\u043d\u0442\u0430 \u0432 bind9 \u0438 \u0434\u0430 \u043d\u0435 \u0441\u0435 \u0431\u0430\u0432\u0438 \u0441 \u043e\u0442\u0433\u043e\u0432\u043e\u0440\u0438\u0442\u0435, \u0434\u0430 \u0432\u0438\u0434\u0438\u043c \u0434\u0430\u043b\u0438 \u0449\u0435 \u0438\u043c\u0430 \u043f\u0440\u043e\u043c\u044f\u043d\u0430.<\/p>\n<p>\u041d\u0430 \u0433\u0440\u0430\u0444\u0438\u043a\u0430\u0442\u0430 \u0433\u043e\u0440\u0435 \u0441\u0438 \u043b\u0438\u0447\u0438 \u043a\u043e\u0433\u0430 \u0441\u044a\u043c \u0441\u043b\u043e\u0436\u0438\u043b \u043e\u043f\u0446\u0438\u0438\u0442\u0435 \u0438 \u043a\u0430\u043a \u0440\u044f\u0437\u043a\u043e \u0441\u0435 \u0435 \u0432\u0434\u0438\u0433\u043d\u0430\u043b \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u043a\u0430\u0442\u043e \u043c\u043e\u0433\u0430 \u0434\u0430 \u043e\u0442\u0433\u043e\u0432\u0430\u0440\u044f\u043c.<\/p>\n<p>\u0421\u043b\u0435\u0434\u0432\u0430\u0449\u043e\u0442\u043e \u0431\u0438 \u0431\u0438\u043b\u043e fail2ban \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0441 ipset-\u043e\u0432\u0435, \u0434\u0430 \u043f\u043e\u0447\u043d\u0430 \u0434\u0430 \u0433\u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u0430\u043c, \u043d\u043e \u043d\u0435 \u0441\u044a\u043c \u0441\u0438\u0433\u0443\u0440\u0435\u043d \u0434\u0430\u043b\u0438 \u0435 \u043f\u043e\u043b\u0435\u0437\u043d\u043e \u0438 \u0434\u0430\u043b\u0438 \u0432\u0441\u0435 \u043f\u0430\u043a \u043d\u044f\u043c\u0430 \u0438 \u043d\u044f\u043a\u0430\u043a\u044a\u0432 \u0440\u0435\u0430\u043b\u0435\u043d \u0442\u0440\u0430\u0444\u0438\u043a \u043e\u0442 \u0442\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u0438, \u0442\u0440\u044f\u0431\u0432\u0430 \u0434\u0430 \u0441\u044a\u0431\u0435\u0440\u0430 \u0436\u0435\u043b\u0430\u043d\u0438\u0435 \u0434\u0430 \u0433\u043e \u0437\u0430\u043f\u0438\u0448\u0430 \u0438 \u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u0430\u043c.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u041d\u043e\u0440\u043c\u0430\u043b\u043d\u0438\u0442\u0435 \u0445\u043e\u0440\u0430 \u0441\u0435 \u0431\u0443\u0434\u044f\u0442 \u0441 \u043a\u0430\u0444\u0435, \u0430\u0437 &#8211; \u0441 DDoS. \u0413\u0440\u0430\u0444\u0438\u043a\u0430 \u043d\u0430 DNS \u0442\u0440\u0430\u0444\u0438\u043a\u0430. \u041d\u0430\u043a\u0440\u0430\u0442\u043a\u043e, \u043e\u0442 \u0432\u0447\u0435\u0440\u0430 \u043d\u044f\u043a\u0430\u043a\u0432\u0438 \u0445\u043e\u0440\u0430 DDoS-\u0432\u0430\u0442 DNS \u0441\u044a\u0440\u0432\u044a\u0440\u0438, \u043f\u043e TCP, \u0441 \u043e\u043f\u0438\u0442 \u0437\u0430 \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u0432\u043d\u0438 resolve-\u0432\u0430\u043d\u0438\u044f, \u043a\u0430\u0442\u043e \u043d\u0435 \u0437\u0430\u0442\u0432\u0430\u0440\u044f\u0442 \u0432\u0440\u044a\u0437\u043a\u0438\u0442\u0435, \u0438 \u0432 \u0435\u0434\u0438\u043d \u043c\u043e\u043c\u0435\u043d\u0442 \u0441\u0432\u044a\u0440\u0448\u0432\u0430 \u043e\u043f\u0430\u0448\u043a\u0430\u0442\u0430 \u043d\u0430 \u0441\u044a\u0440\u0432\u044a\u0440\u0430. \u0412 \u043b\u043e\u0433\u043e\u0432\u0435\u0442\u0435 \u0441\u0438 \u043b\u0438\u0447\u0438 \u043f\u043e Mar 31 10:16:48 marla named[221347]: client @0x7f2263433c98 177.54.96.29#40555 (arvika.se): [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[16],"class_list":["post-3525","post","type-post","status-publish","format-standard","hentry","category-general","tag-16"],"_links":{"self":[{"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3525"}],"version-history":[{"count":0,"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3525\/revisions"}],"wp:attachment":[{"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vasil.ludost.net\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}