Closed Benjamin-Loison closed 5 months ago
From support@ovh.com at 04:37:
[CENSORED-ovh] Protection anti-DDoS sur 54.37.228.22 : retour à la normale
SAS OVH - https://www.ovh.com/ 2 rue Kellermann BP 80157 59100 Roubaix
Chère cliente, cher client,
Nous vous informons que nous n'observons plus de flux inhabituels pour les adresses IP listées.
L'infrastructure anti-DDoS revient maintenant en mode par défaut.
Nous vous remercions pour la confiance que vous nous accordez.
L'équipe OVHcloud
Pour obtenir de l'aide, retrouvez toutes nos solutions en ligne sur notre Centre d'aide : https://help.ovhcloud.com/ Vous y retrouverez nos Guides, FAQ, Forum communautaire et Opérations de maintenance.
OVH SAS est une filiale de la société OVH Groupe SAS, SAS au capital de 10 069 020 euros, immatriculée au RCS de Lille Métropole sous le numéro 537 407 926 et dont le siège social est sis 2, rue Kellermann, 59100 Roubaix. [ref=CENSORED]
https://discord.com/channels/933841502155706418/933841503103627316/1249908624843870301
At 03:43:
From: support@ovh.com
From my laptop:
I already
reboot
ted the server and verified its DNS withservice bind9 status
.https://www.ovh.com/manager/#/web/zone/lemnoslife.com
https://www.ovh.com/manager/#/dedicated/vps/vps713872.ovh.net/dashboard
Source: https://www.ovh.com/manager/#/web/domain
https://www.ovh.com/manager/#/web/domain/lemnoslife.com
/etc/bind/db.lemnoslife.com
:Should investigate:
https://arstechnica.com/gadgets/2020/08/understanding-dns-anatomy-of-a-bind-zone-file/
Investigating how Firefox DNS over HTTPS with CloudFlare works:
The few results on DuckDuckGo and Google for
"#53: timed out"
do not look interesting.Should investigate https://www-phpschool-com.translate.goog/gnuboard4/bbs/board.php?bo_table=qna_install&wr_id=130170&sca&page=4&_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp.
/etc/resolv.conf
:From my OVH VPS:
Maybe the anti DDOS is just forbidding external access.
It seems to make sense as there is no
End time
to current attack:Source: https://www.ovh.com/manager/#/dedicated/network-security/scrubbing-center
So it does not seem possible to tell OVH that it is filtering too much.
Source: https://www.ovh.com/manager/#/dedicated/network-security/traffic
According to history entries 26 hours after
Detection time
there is theEnd time
, so in theory around2024-06-12 04:36:59
.Both:
mentions
213.186.33.99
in/etc/resolv.conf
.https://www.zonemaster.net/en/run-test
I personally modified my
/etc/hosts
to not suffer of this issue.