Skip to content

Comment on DDOS on Namecheap Free DNS and Default DNS V2parent

Comments

Just for future reference, it's usually considered a good idea to put your status page on completely independent infrastructure so that it stays up even when the rest of your stuff goes down. A status page that doesn't work during an outage isn't particularly useful.

Good point. The status page is on another cloud but since this is a DNS issue, the subdomain is down. In the future, we'll investigate running this page on a secondary DNS.

According to whois for namecheap.com, the DNS for that domain is hosted on dynect.net, and "host status.namecheap.com" resolves just fine (to 204.232.212.56), so it does not appear to be a DNS issue that is preventing your status page from working.

I stand corrected. It's on Rackspace, which apparently is also experiencing issues.

Rackspace helped us get our status page back online: http://status.namecheap.com/

Perhaps also investigate allowing customers to slave their own secondary DNS, too? (That is, allow AXFRs.)

This has been a feature requested for, as far as I can tell from the support forums, four years now. It should be possible to make this allowed/disallowed per-zone, and as far as I'm concerned, I don't care who is able to download my tiny zone file. It would allow me to add more diversified DNS servers in the face of things like a DoS against Namecheap.

Posting up-to-the-minute updates on Twitter is also a good idea. Lots of tweets come back from a search for "Namecheap" & you want to be sure you're a part of that conversation!

They've been posting updates 30 minutes before your post buddy, and still are now. https://twitter.com/Namecheap

Yes, we are actively posting updates on Twitter.

If the hackers really want to take you down, adding another server in isn't very hard...

If you're as big as NameCheap, you can afford to pay CloudFlare or somebody like it to protect your status page.

Cloudflare has also been nailed the last 3 weeks in a row causing outages. Just search Twitter for cloudflare DDOS or NTP or etc. etc. etc. At the end of the day there are currently so many slave machines out there we are all vulnerable. It's just the nature of things. At least outages are only temporary. It's much better than the early days were we'd be down for 12 hours at a time. https://twitter.com/search?q=cloudflare%20attack&src=typd

I suspect the hackers are targeting one of namecheap's customers, not namecheap directly. Because that's usually the case, a good approach is to not give all customers the exact same nameservers.

I agree. We left Network Solutions b/c they were hit 3 times in less than a year. Maybe the website targets moved to Namecheap, so they were targeted also?

Like!

Not having separate status hosting is liken not salting passwords. As a NC user, I may leave just for this reason

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.