Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification Attacks
Maynard Koch, Florian Dolzmann, Thomas C. Schmidt, Matthias Wählisch
TL;DR
Transparent DNS forwarders form a large, under-secured portion of the open DNS infrastructure and enable scalable reflective amplification by bypassing source-address rewrites. The authors combine internet-wide measurements, controlled lab experiments, and fingerprinting to quantify prevalence, rate limits, and amplification potential, demonstrating up to $14\times$ scaling via anycast backends and substantial throughput gains over recursive forwarders. They show how TFs bypass firewalled resolvers and rate limits, and how orchestration across global TFs can induce high-volume, geographically distributed attacks. The work provides concrete mitigation options (ingress filtering, RP filtering, firewall hardening) and highlights the need for ongoing measurement and defender awareness, aided by responsible disclosure that reduced the attack surface by about 30%. Overall, the study reveals a tangible, global threat surface posed by transparent forwarders and offers practical guidance for DNS operators and policymakers to tighten defenses.
Abstract
The DNS infrastructure is infamous for facilitating reflective amplification attacks. Various countermeasures such as server shielding, access control, rate limiting, and protocol restrictions have been implemented. Still, the threat remains throughout the deployment of DNS servers. In this paper, we report on and evaluate the often unnoticed threat that derives from transparent DNS forwarders, a widely deployed, incompletely functional set of DNS components. Transparent DNS forwarders transfer DNS requests without rebuilding packets with correct source addresses. As such, transparent forwarders feed DNS requests into (mainly powerful and anycasted) open recursive resolvers, which thereby can be misused to participate unwillingly in distributed reflective amplification attacks. We show how transparent forwarders raise severe threats to the Internet infrastructure. They easily circumvent rate limiting and achieve an additional, scalable impact via the DNS anycast infrastructure. We empirically verify this scaling behavior up to a factor of 14. Transparent forwarders can also assist in bypassing firewall rules that protect recursive resolvers, making these shielded infrastructure entities part of the global DNS attack surface.
