Comment by charcircuit
1 day ago
>to figure out which records to avoid
It is more likely they were looking for a DNS server with a big response packet for use in amplified DDoS attacks.
1 day ago
>to figure out which records to avoid
It is more likely they were looking for a DNS server with a big response packet for use in amplified DDoS attacks.
No they were specifically trying and failing of course to AXFR from the only domains I had added the zeroconf addresses to and shortly thereafter all the scanning went quiet. If they were not skiddies they could have just updated their tools to ignore private address spaces from all domains all together. Don't worry, I am not reporting them.
There are loads of big TXT records on many domains that can be used for amplification attacks. [1] These are just a few by the way, I transparently filter many TXT records on some DNS servers for this reason.
[1] - https://news.ycombinator.com/item?id=48599363