GoDaddy Target of Major Attack by Hacker

jsherm101 0 Tallied Votes 664 Views Share

Over the last few hours of the day GoDaddy's (and GoDaddy managed) websites have been on the fritz as webmasters and visitors alike are unable to access millions of websites held within GoDaddy's datacenters in an apparent Denial of Service (DDOS) attack. GoDaddy is currently scrambling to restore service to their customers at this very moment.

The individual claiming responsibility for the attack claims to be a member of the internet group Anonymous, though he acted alone and not with the collective organization. Anonymous is infamous for a variety of attacks on various websites & services, including the recent leaking of sensitive Apple data from Blue Toad, an analytics company that was collecting UDID information, like a serial number for iOS devices, that could be used for malicious activities in the wrong hands.

The belief at the moment is that the attack is not a traditional Denial-of-Service, where the attack is attempting to overload traffic to all of GoDaddy's servers, but instead a attack on the DNS servers that controls the redirecting of users from domain names (like www.DaniWeb.com) to the correct server IP Address of the website. Specific DNS servers that are unavailable at this time include secureserver.com, domancontrol.com, and others, though GoDaddy is trying hard to restore service at this time.

While no motive has yet been stated, GoDaddy has historically been a target to significant criticism from many internet communities due to their large size, support of the anti-privacy SOPA law (before changing their stance,) and various other incidents of controversy, the circumstances are also different, as the Denial-of-Service attack on DNS servers effects customers of GoDaddy far more than the company itself, and peak downtime estimates suggest as many as 48 million websites were affected by the attack.

While such an attack is directed toward GoDaddy perhaps for reasons previously mentioned, it should be noted this situation is possible with any web host, as DNS servers are the foundation of how requests to visit websites are made, and all of them are subject to the risk of a Denial-of-Service attack.

As of 5:00 PM EST, service for many GoDaddy websites has not yet been restored, and the DNS servers previously mentioned still remain out of service.

Dani AI

Generated

A short, practical addendum to the thread by and : the Sep 10, 2012 incident that disrupted many GoDaddy-hosted sites was widely reported at the time, and company statements and follow-up reporting concluded the outage stemmed from internal network/router problems rather than a confirmed external DDoS. (arstechnica.com)

If a hosted site looks down and you suspect DNS is involved, run a few quick checks from multiple places (your machine, a public resolver, and a remote host): query the authoritative nameservers, perform a trace, and look at NS/SOA/TTL values. Useful commands: dig +trace example.com, dig +short NS example.com, dig @8.8.8.8 example.com. Remember that cached answers respect TTLs so resolution can appear inconsistent until caches expire; flush local caches while you troubleshoot. (man.openbsd.org)

Hardening advice for site owners (practical, low-effort steps): use a secondary or multi-provider DNS setup (so authoritative records remain resolvable if one vendor has trouble), prefer Anycast-backed authoritative DNS or a reputable CDN for static content, keep registrar credentials separate from your hosting account, export and archive your zone file, and test failover and monitoring regularly. These are common resilience recommendations in modern DNS guidance and security practice. ()

Quick checklist to follow now: 1) confirm whether the issue is DNS vs. origin (use the dig checks above); 2) read your DNS provider’s status page/postmortem; 3) ensure you can update NS records at the registrar; 4) lower TTLs before planned moves and raise them afterward; 5) implement passive monitoring/alerts for DNS resolution failures; 6) if you believe you’re under attack, follow incident reporting and escalation guidance with your ISP/registrar and national CERT. ()

These steps won’t stop every outage, but they reduce single points of failure and give site owners concrete recovery options when DNS problems surface.

Member Avatar for Member #949455
Member #949455

You need to update your article it's working on.

jsherm101 14 Light Poster

Actually at about 8PM I was going to post an update it was back up for most services - and by 9PM nearly them all. Sorry about that!

If you are still experiencing problems, it's suggested you contact GoDaddy Support via telephone (480) 505-8877 or by visiting www.GoDaddy.com

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.