Remove Advertising Remove DNS Remove UDP port
article thumbnail

AWS Route 53 BGP Hijack: What Kentik Saw

Kentik

During a BGP route hijack, an attacker advertises IP prefixes from an ASN that is not the normal originator. During last week’s attack, the attacker was redirecting traffic that belonged to Amazon’s Route 53 DNS servers. Here we have the DNS clients sending their DNS queries to the hijacked blocks advertised by AS10297.