<html><head>
<meta content="text/html; charset=ISO-8859-1" http-equiv="Content-Type">
</head><body bgcolor="#FFFFFF" text="#000000"><br>
<br>
<blockquote style="border: 0px none;" 
cite="mid:20141210125546.GA912@nic.fr" type="cite">
  <div style="margin:30px 25px 10px 25px;" class="__pbConvHr"><div 
style="display:table;width:100%;border-top:1px solid 
#EDEEF0;padding-top:5px">       <div 
style="display:table-cell;vertical-align:middle;padding-right:6px;"><img
 photoaddress="bortzmeyer@nic.fr" photoname="Stephane Bortzmeyer" 
src="cid:part1.04000505.04000905@dnsbed.com" 
name="compose-unknown-contact.jpg" height="25px" width="25px"></div>   <div
 
style="display:table-cell;white-space:nowrap;vertical-align:middle;width:100%">
        <a moz-do-not-send="true" href="mailto:bortzmeyer@nic.fr" 
style="color:#737F92 
!important;padding-right:6px;font-weight:bold;text-decoration:none 
!important;">Stephane Bortzmeyer</a></div>   <div 
style="display:table-cell;white-space:nowrap;vertical-align:middle;">   
  <font color="#9FA2A5"><span style="padding-left:6px">2014年12月10日下午8:55</span></font></div></div></div>
  <div style="color:#888888;margin-left:24px;margin-right:24px;" 
__pbrmquotes="true" class="__pbConvBody"><div>On Tue, Dec 02, 2014 at 
02:01:48PM +0800,<br> Ken Peng <a class="moz-txt-link-rfc2396E" href="mailto:yhpeng@orange.fr"><yhpeng@orange.fr></a> wrote <br></div><div><!----><br>By
 the way, they published a good technical report:<br><br><a class="moz-txt-link-freetext" href="http://blog.dnsimple.com/2014/12/incident-report-ddos/">http://blog.dnsimple.com/2014/12/incident-report-ddos/</a><br>_______________________________________________<br>dns-operations
 mailing list<br><a class="moz-txt-link-abbreviated" href="mailto:dns-operations@lists.dns-oarc.net">dns-operations@lists.dns-oarc.net</a><br><a class="moz-txt-link-freetext" href="https://lists.dns-oarc.net/mailman/listinfo/dns-operations">https://lists.dns-oarc.net/mailman/listinfo/dns-operations</a><br>dns-jobs
 mailing list<br><a class="moz-txt-link-freetext" href="https://lists.dns-oarc.net/mailman/listinfo/dns-jobs">https://lists.dns-oarc.net/mailman/listinfo/dns-jobs</a><br></div></div>
</blockquote>
<br>
<span>UDB is hard to be defensed, as the spooled IPs are hard to setup 
the correct firewall rules.  <br>
Can we guess the next generation of DNS will service primarily using 
TCP? </span><br>
<br>
<div class="moz-signature">-- <br>Best Regards,<br>


<a href="http://www.dnsbed.com/">DNSbed Hosting</a><br>


<br>

</div>
</body></html>