Welp it just looked like a DNS inject attack....so here's what happened. 1. A JunOS upgrade was done to the main UH routers, which had some adverse effects 2. that caused all the UH DNS servers and such to disappear from the face of the earth 3. one particular domain was registered on GoDaddy that was in an address space VERY similar to what the Chinese MSS uses for attacks 4. So on campus the domain goes to UH address space, but in the outside world it goes to GoDaddy who then redirects to a UH address.
So it was just a weird happenstance....not a real attack. /brian chee On Wed, May 28, 2014 at 1:32 PM, Jeff Mings <je...@lava.net> wrote: > Huh. I often use mirror.ancl.hawaii.edu, but I'm also interested in > hearing a bit more about the DNS attack. > > Good Luck, > -Jeff > > > On 05/28/2014 09:34 AM, Brian Chee wrote: > >> UH is being hit by a DNS inject attack and things are kinda messed up at >> the moment. Will keep you posted when things settle down. I'm only able to >> send email because I'm on WIMax at the moment. >> >> /brian chee >> >> >> > _______________________________________________ > LUAU@lists.freesoftwarehawaii.org mailing list > http://lists.freesoftwarehawaii.org/listinfo.cgi/luau- > freesoftwarehawaii.org > -- ******************************************** University of Hawaii SOEST Advanced Network Computing Laboratory (ANCL) Brian Chee <c...@hawaii.edu> 2525 Correa Road, HIG 500 Honolulu, HI 96822 Office: 808-956-5797 _______________________________________________ LUAU@lists.freesoftwarehawaii.org mailing list http://lists.freesoftwarehawaii.org/listinfo.cgi/luau-freesoftwarehawaii.org