
A technique called Pseudo Random Subdomain Attack (PRSD), which uses DNS for non-existent and random subdomains, was used by hackers to carry out DDoS on voter websites in the US.
According to the FBI, malicious users have carried out attacks against government websites targeting American voters.
“The FBI has received reports indicating that state voter registration websites and voter information websites have been receiving suspicious DNS (Domain Name System) requests as a result of a Pseudo Random Subdomain (PRSD) attack,” states an alert sent by the FBI and published by BleepingComputer.
“The requests occurred over the course of at least a month at intervals of approximately two hours, with a frequency of around 200,000 DNS requests, during a period when requests are normally less than 15,000 for this particular website.”.
PRSD attacks can be dangerous if DNS servers do not have the appropriate tools to deal with such incidents. However, in this case, this did not happen, since the servers had rate-limiting algorithms that help control incoming and outgoing traffic.
These types of DDoS attacks are used because they make it easier to spoof the source, as requests can be routed through open proxies and botnets. On the other hand, it is not that difficult to protect yourself from such an attack.
The FBI advises institutions and companies to have a plan in place to deal with such incidents, including a DDoS mitigation strategy, to keep all endpoints, hardware and software up to date, and to maintain a timeline for attacks. Of course, organizations in the United States are advised to contact the FBI in the event of a DDoS attack.
