Perfect is the enemy of good enough.

Strange DNS queries: qname "miep", qtype ANY

Posted May 03, 2019 by shaun

One of my DNS servers has been seeing some unusual bursts of traffic over the past month. At random intervals, several hundred rapid queries for qname miep and qtype ANY will arrive, appearing in BIND's security log like this:

03-May-2019 16:05:18.430 security: info: client @0x7f392c0bcfe0 (miep): query (cache) 'miep/ANY/IN' denied
03-May-2019 16:05:18.430 security: info: client @0x7f392c0bcfe0 (miep): query (cache) 'miep/ANY/IN' denied
03-May-2019 16:05:18.430 security: info: client @0x7f392c0cb600 (miep): query (cache) 'miep/ANY/IN' denied
03-May-2019 16:05:18.430 security: info: client @0x7f392c0bcfe0 (miep): query (cache) 'miep/ANY/IN' denied

At first glance, this resembles a DNS amplification attack. For one thing, the deprecated ANY qtype is used in such attacks to maximize the size of the answer packets. Secondly, the origin IPs are probably forged, considering the legitimate resolver has been among them. Trouble is, there's no such zone as miep, so there's nothing to amplify here (and my servers wouldn't answer that query, regardless). If this is supposed to be part of a DDoS, it looks like an abject failure.

Some other observations about this traffic:

  • I run several authoritative DNS servers, but only one is seeing this traffic
  • The resolver being queried is not and has never been an open recursive resolver
  • I can only find one other report of this behavior
  • The questioned traffic is increasing, both in query volume and in the number of origins (targets)
  • Most of the IPs involved are Netherlands-based VPSes or residential broadband connections

I've posted a log of observed queries (~2.4 MB) as of 2019-08-17.

I'm used to DNS recon noise as bots scan the world for open resolvers, but this traffic is just weird. If you have any idea what's responsible for it, please reply to this tweet.

📰 Strange DNS queries: qname "miep", qtype ANY

