We received a security alert from the German Federal Office for Information Security (BSI).
Please see the original report included below for details.
Please investigate and solve the reported issue.
It is not required that you reply to either us or the BSI.
If the issue has been fixed successfully, you should not receive any further notifications.
Additional information is provided with the HOWTOs referenced in the report.
In case of further questions, please contact
certbund@bsi.bund.de and keep the
ticket number of the original report [CB-Report#...] in the subject line.
Do not reply <reports@reports.cert-bund.de> as this is just the sender address for the
reports and messages sent to this address will not be read.
Kind regards
Abuse team
On 28 Mar 12:50,
reports@reports.cert-bund.de wrote:
> Dear Sir or Madam,
>
> over the past months, DDoS reflection attacks using DNS amplification
> significantly increased, with a huge number of open DNS resolvers
> hosted in Germany participating in the attacks against third parties.
>
> Affected systems on your network:
>
> Format: ASN | IP | Timestamp (UTC)
> 24949.58 | 20-27 00:29
>
> We would like to ask you to check if the open resolvers identified
> on your network are intentionally configured as such and appropriate
> countermeasures preventing their abuse for DDoS attacks have been
> implemented.
>
> If you have recently solved the issue but received this notification
> again, please note the timestamp included below. You should not
> receive any further notifications with timestamps after the issue
> has been solved.
>
> Additional information on this notification, advice on how to fix
> reported issues and answers to frequently asked questions:
> <https://reports.cert-bund.de/en/>
>
> This message is digitally signed using PGP.
> Information on the signature key is available at:
> <https://reports.cert-bund.de/en/digital-signature>
>
> Please note:
> This is an automatically generated message. Replies to the
> sender address <reports@reports.cert-bund.de> will NOT be read
> but silently be discarded. In case of questions, please contact
> <certbund@bsi.bund.de> and keep the ticket number [CB-Report#...]
> of this message in the subject line.
>
> !! Please make sure to consult our HOWTOs and FAQ available at
> !! <https://reports.cert-bund.de/en/> first.
>