September 26, 2019

Edu.za being used to send insane amounts of DDoS attack traffic

Domain Name System (DNS) servers on thedu.za domain are being exploited to launch massive distributed denial of service attacks (DDoS). Nexusguard reported that edu.za had 13,524,481 spoofed DNS requests last quarter, accounting for 9.36% of all DNS abuse. Nexusguard’s Q2 2019 Threat Report stated that DNS amplification attacks have spiked more than 1,000% compared with Q2 2018. It attributed this rise to the adoption of Domain Name System Security Extensions (DNSSEC) without proper precautions in place to mitigate DNS-amplified DDoS attacks.

