[dns-operations] Questions about 13-character pseudo-random query storms

Peter van Dijk peter.van.dijk at powerdns.com
Thu Oct 11 21:51:15 UTC 2018


On 10 Oct 2018, at 8:34, Dobbins, Roland wrote:

>> That's indeed puzzling.
>
> It looks like DGA stuff, to me.  The 13-character length argues 
> against
> enumeration.

Enumeration in NSEC3 zones means hitting as many hashed NSEC3 spans as 
possible (to gather data for offline brute forcing). Why does the length 
argue against that?

Kind regards,
-- 
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/



More information about the dns-operations mailing list