{"id":33217,"date":"2020-05-05T18:23:00","date_gmt":"2020-05-05T15:23:00","guid":{"rendered":"https:\/\/www.natro.com\/blog\/?p=33217"},"modified":"2022-04-12T18:28:32","modified_gmt":"2022-04-12T15:28:32","slug":"dns-amplification-saldirisindan-korunma-dns-recursion-update","status":"publish","type":"post","link":"https:\/\/www.natro.com\/blog\/dns-amplification-saldirisindan-korunma-dns-recursion-update\/","title":{"rendered":"DNS Amplification Sald\u0131r\u0131s\u0131ndan Korunma: DNS Recursion Update"},"content":{"rendered":"\n<p><strong>DNS Amplification<\/strong> bir t\u00fcr DDoS sald\u0131r\u0131s\u0131d\u0131r. Bu sald\u0131r\u0131n\u0131n amac\u0131, kullan\u0131c\u0131lar\u0131n a\u011f \u00fczerinde bulunan sistemlere eri\u015fimini yava\u015flatarak bir web sitesine veya uygulamaya eri\u015fim sa\u011flamalar\u0131n\u0131 engellemektir.<\/p>\n\n\n\n<p>Bu sald\u0131r\u0131dan korunmak i\u00e7in <strong>cPanel<\/strong>, <strong>Plesk<\/strong>,<strong> Ubuntu <\/strong>ve<strong> Windows Server<\/strong> kullanan sunucular\u0131n\u0131z i\u00e7in yapabilece\u011finiz <strong>DNS Recursion Update <\/strong>i\u015fleminden bahsedece\u011fiz.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-1-cpanel-sunucu-ayarlari\"><span id=\"1-cpanel-sunucu-ayarlari\"><strong>1- cPanel \u2013 Sunucu Ayarlar\u0131<\/strong><\/span><\/h2>\n\n\n\n<p>SSH ba\u011flant\u0131s\u0131 sa\u011flad\u0131ktan sonra a\u015fa\u011f\u0131daki komut ile DNS Recursion mevcut ayarlar\u0131n\u0131 g\u00f6r\u00fcnt\u00fclemi\u015f olaca\u011f\u0131z.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>cat \/etc\/named.conf | grep \u201crecursion\u201d<\/p><\/blockquote>\n\n\n\n<div class=\"wp-block-image size-full wp-image-29900\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion1.png\" alt=\"\" class=\"wp-image-29900\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<p>Dikkat etmemiz gerek konu burada d\u0131\u015far\u0131ya do\u011fru dns recursion i\u015fleminin a\u00e7\u0131k olup olmad\u0131\u011f\u0131n\u0131 kontrol etmektir. Bunun i\u00e7in a\u015fa\u011f\u0131daki komut ile ilgili dosya i\u00e7eri\u011fine eri\u015fim sa\u011flay\u0131p CTRL + W ile \u201c<strong>externa<\/strong>l\u201d kelimesini aratal\u0131m.<\/p>\n\n\n\n<p>\u201cnano kurulu de\u011fil ise <strong>Centos<\/strong> i\u00e7in \u201cyum install nano\u201d <strong>Ubuntu<\/strong> i\u00e7in \u201capt install nano\u201d kullanabilirsiniz.\u201d<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Nano \/etc\/named.conf<\/p><\/blockquote>\n\n\n\n<div class=\"wp-block-image wp-image-29903 size-full\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion2.png\" alt=\"\" class=\"wp-image-29903\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<p>Burada g\u00f6r\u00fclece\u011fi \u00fczere \u201c<strong>external<\/strong>\u201d b\u00f6l\u00fcm\u00fcnde recursion \u201c<strong>yes<\/strong>\u201d g\u00f6r\u00fclmekte bunu \u201c<strong>no<\/strong>\u201d olarak g\u00fcncelledikten sonra <strong>CTRL + X<\/strong> ile kaydedip \u00e7\u0131k\u0131\u015f yap\u0131yoruz. Bu i\u015flemden sonra yapmam\u0131z gereken tek i\u015flem dns servisini yeniden ba\u015flatmak olacakt\u0131r. A\u015fa\u011f\u0131daki komut ile servisi yeniden ba\u015flatabiliriz.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>service named restart<\/p><\/blockquote>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion3.png\" alt=\"\" class=\"wp-image-29904\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-2-plesk-sunucu-ayarlari\"><span id=\"2-plesk-sunucu-ayarlari\"><strong>2- Plesk \u2013 Sunucu Ayarlar\u0131<\/strong><\/span><\/h2>\n\n\n\n<p>Plesk \u00fczerinde dns recursion i\u015flemini kontrol etmek ve iptal etmek i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izlememiz gerekiyor. \u00d6ncelikle <strong>ipadresiniz:8443<\/strong> olarak Plesk panelinize en y\u00fcksek yetki ile giri\u015f yap\u0131n\u0131z.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Ipadresiniz: 8443\/admin\/server\/tools?context=tools<\/p><\/blockquote>\n\n\n\n<p>Giri\u015f sa\u011flad\u0131ktan sonra sol tarafta bulunan Ara\u00e7lar ve Ayarlar sekmesi i\u00e7erisindeki DNS \u015eablonu se\u00e7ene\u011fini se\u00e7ece\u011fiz.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion4.png\" alt=\"\" class=\"wp-image-29905\"\/><\/figure>\n\n\n\n<p>DNS RecursionDNS \u015eablonu i\u00e7erisinde DNS \u00d6nyinelemesi (recursion) sekmesine ge\u00e7i\u015f sa\u011flayal\u0131m.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion5.png\" alt=\"\" class=\"wp-image-29906\"\/><\/figure>\n\n\n\n<p>\u0130lgili sekme i\u00e7erisinden Yaln\u0131zca yerel isteklere izin ver se\u00e7ene\u011fini se\u00e7ip ata butonu ile i\u015flemi kay\u0131t edelim.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion6.png\" alt=\"\" class=\"wp-image-29907\"\/><\/figure>\n\n\n\n<p>Plesk panel kullan\u0131c\u0131lar\u0131 SSH ba\u011flant\u0131s\u0131 sa\u011flamadan panel \u00fczerinden bu i\u015flemi kolayl\u0131kla ger\u00e7ekle\u015ftirebilirler.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-3-ubuntu-sunucu-ayarlari\"><span id=\"3-ubuntu-sunucu-ayarlari\"><strong>3- Ubuntu \u2013 Sunucu Ayarlar\u0131<\/strong><\/span><\/h2>\n\n\n\n<p>Ubuntu i\u015fletim sistemine sahip bir sunucu kullan\u0131yorsan\u0131z terminal ekran\u0131na a\u015fa\u011f\u0131daki komutu yap\u0131\u015ft\u0131rman\u0131z yeterli.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>perl -pi -e \u2018s\/recursion yes\/recursion no\/g\u2019 \/etc\/bind\/named.conf;service bind9 restart<\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-4-windows-server-2012-ve-uzeri-sunucu-ayarlari\"><span id=\"4-windows-server-2012-ve-uzeri-sunucu-ayarlari\"><strong>4- Windows Server 2012 ve \u00dczeri Sunucu Ayarlar\u0131<\/strong><\/span><\/h2>\n\n\n\n<p>Ba\u015flat \u00fczerinden arama b\u00f6l\u00fcm\u00fcne Powershell yazarak ilgili ekranda \u00e7\u0131kan Powershell arac\u0131n\u0131 \u00e7al\u0131\u015ft\u0131ral\u0131m.<\/p>\n\n\n\n<div class=\"wp-block-image wp-image-29908 size-full\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion7.png\" alt=\"\" class=\"wp-image-29908\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<p>\u0130lgili araca eri\u015fim sa\u011flad\u0131ktan sonra a\u015fa\u011f\u0131da yer alan komutu sat\u0131ra yap\u0131\u015ft\u0131r\u0131p uygulayal\u0131m.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Set-DnsServerRecursion -Enable 0<\/p><\/blockquote>\n\n\n\n<div class=\"wp-block-image size-full wp-image-29909\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion8.png\" alt=\"\" class=\"wp-image-29909\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<p>\u0130lgili komutu uygulad\u0131ktan sonra \u00e7\u0131kt\u0131m\u0131z a\u015fa\u011f\u0131daki \u015fekilde bo\u015f olacakt\u0131r.<\/p>\n\n\n\n<div class=\"wp-block-image size-full wp-image-29910\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion9.png\" alt=\"\" class=\"wp-image-29910\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-5-windows-server-2003-ve-2008-sunucu-ayarlari\"><span id=\"5-windows-server-2003-ve-2008-sunucu-ayarlari\"><strong>5- Windows Server 2003 ve 2008 \u2013 Sunucu Ayarlar\u0131<\/strong><\/span><\/h2>\n\n\n\n<p><strong>Ba\u015flat -> \u00c7al\u0131\u015ft\u0131r -> CMD<\/strong> veya arama b\u00f6l\u00fcm\u00fcne cmd yaz\u0131p y\u00f6netici olarak \u00e7al\u0131\u015ft\u0131rabilirsiniz. <strong>CMD<\/strong> ekran\u0131na eri\u015fim sa\u011flad\u0131ktan sonra a\u015fa\u011f\u0131daki komutu i\u015fleyebilirsiniz.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Dnscmd \/Config \/NoRecursion 1<\/p><\/blockquote>\n\n\n\n<p>veya alternatif ad\u0131mlar\u0131 inceleyebilirsiniz.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion10.png\" alt=\"\" class=\"wp-image-29911\"\/><\/figure>\n\n\n\n<p>Windows sunucumuza ba\u011flant\u0131 sa\u011flad\u0131ktan sonra arama b\u00f6l\u00fcm\u00fcne DNS yazarak ilgili servise giri\u015f yapal\u0131m.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion11.png\" alt=\"\" class=\"wp-image-29912\"\/><\/figure>\n\n\n\n<p>Servis ekran\u0131 a\u00e7\u0131ld\u0131ktan sonra makine ad\u0131n\u0131z\u0131n yazd\u0131\u011f\u0131 kutucu\u011fa sa\u011f t\u0131klay\u0131p \u00f6zellikler se\u00e7ene\u011fi ile detaylar\u0131na giri\u015f yapal\u0131m.<\/p>\n\n\n\n<div class=\"wp-block-image size-full wp-image-29913\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion12.png\" alt=\"\" class=\"wp-image-29913\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<p>Detaylara giri\u015f sa\u011flad\u0131ktan sonra <strong>Advanced<\/strong> sekmesine ge\u00e7i\u015f yapal\u0131m.<\/p>\n\n\n\n<div class=\"wp-block-image size-full wp-image-29914\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion13.png\" alt=\"\" class=\"wp-image-29914\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n\n\n\n<p>\u0130lgili sekmede DNS Recursion se\u00e7ene\u011fini g\u00f6r\u00fcnt\u00fclemi\u015f olaca\u011f\u0131z. Bu se\u00e7ene\u011fi i\u015faretledikten sonra kaydedip \u00e7\u0131k\u0131\u015f yapabiliriz.<\/p>\n\n\n\n<div class=\"wp-block-image size-full wp-image-29915\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.natro.com\/blog\/wp-content\/uploads\/2020\/05\/DNS-Recursion14.png\" alt=\"\" class=\"wp-image-29915\"\/><figcaption>DNS Recursion<\/figcaption><\/figure><\/div>\n","protected":false},"excerpt":{"rendered":"DNS Amplification bir t\u00fcr DDoS sald\u0131r\u0131s\u0131d\u0131r. Bu sald\u0131r\u0131n\u0131n amac\u0131, kullan\u0131c\u0131lar\u0131n a\u011f \u00fczerinde bulunan sistemlere eri\u015fimini yava\u015flatarak bir web&hellip;\n","protected":false},"author":7,"featured_media":30018,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28,36],"tags":[],"class_list":{"0":"post-33217","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-nasil-yapilir","8":"category-sunucu"},"_links":{"self":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts\/33217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/comments?post=33217"}],"version-history":[{"count":1,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts\/33217\/revisions"}],"predecessor-version":[{"id":33218,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/posts\/33217\/revisions\/33218"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/media\/30018"}],"wp:attachment":[{"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/media?parent=33217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/categories?post=33217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.natro.com\/blog\/wp-json\/wp\/v2\/tags?post=33217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}