The principle is simple; a flaw that uses forged UDP packets is to be
used to trigger a rush of DNS queries all redirected and reflected to
those 13 IPs. The flaw is as follow; since the UDP protocol allows it,
we can change the source IP of the sender to our target, thus spoofing
the source of the DNS query.
The DNS server will then respond to that query by sending the answer to
the spoofed IP. Since the answer is always bigger than the query, the
DNS answers will then flood the target ip. It is called an amplified
because we can use small packets to generate large traffic. It is called
reflective because we will not send the queries to the root name servers,
instead, we will use a list of known vulnerable DNS servers which will
attack the root servers for us.
* Verisign, because they inherited MCI and thus UUNet.
* USC, one of the headquarters of academic network research.
* Cogent (no idea why, but they're a sort-of tier 1 NSP).†
* UMD, another headquarters of academic network research.
* NASA, because space.
* ISC, because they organized the authorship of BIND.
* DISA, because of DARPA.
* Army Research Lab, because of .MIL.
* Whoever owns NORDU.NET, which was is a consortium of Nordic network academics.
* Verisign because they stole it from Thráin II during their final captivity in Dol Guldur.
* RIPE, because they number Europe.
* ICANN, because they ostensibly oversee the whole DNS.
* WIDE because they're like the NORDU or MERIT of Japan.
Most of this, if you can't tell, is an artifact of which organizations built the instance of the Internet that caught on in the '90s (I was going to say "that built the commercial Internet", but they didn't mostly didn't realize that was what they were doing when they did it).
Fun fact: in the early '90s, there were actual Internet netsplits, like you see on IRC, but across the Internet. Ripco, my ISP at the time, lost access to NSFNet and all of .EDU.
No, you can't add your company to this list.
† Aha, it's Cogent because they bought PSI, and it was PSI because they helped build NSFNet and CIX.
Not only are there more than 13 of them, most of the root servers are now being served by anycast, so the same IP address corresponds to many servers around the globe.
The principle is simple; a flaw that uses forged UDP packets is to be used to trigger a rush of DNS queries all redirected and reflected to those 13 IPs. The flaw is as follow; since the UDP protocol allows it, we can change the source IP of the sender to our target, thus spoofing the source of the DNS query.
The DNS server will then respond to that query by sending the answer to the spoofed IP. Since the answer is always bigger than the query, the DNS answers will then flood the target ip. It is called an amplified because we can use small packets to generate large traffic. It is called reflective because we will not send the queries to the root name servers, instead, we will use a list of known vulnerable DNS servers which will attack the root servers for us.