9 ms·
Bitsquatting Windows.com
- viraptor 6y agoWhat I'd love to see is a split by which bit is affected and are any versions more popular in the truly benign cases (like ntp). Although it was confirmed with idle devices that we do see bitflips, I keep wondering if in real world we get more changes due to memory overflows than cosmic rays / failed ram refresh.
- AdamJacobMuller 6y agoI did this years ago with the DNS name for a large CDN (think akadns.net but it wasn't Akamai) and also saw lots of interesting stuff behind it. Its hard (maybe impossible) to identify identify scale, so I don't know if it was 1%, .1% or .0001% of traffic, but I was seeing hundreds of requests per second.
- hanniabu 6y agoSince you have experience, maybe there's something you can help explain with what was mentioned: > In fact, out of the 32 valid domain names that are 1-bitflip away from windows.com "windows" is 7 characters long so how is there 32 1-bitflip combinations? Also one of the ones mentioned was "windo7s", but "w" is 01111000 and "7" is 0000111, which isn't a single bit flip away unless I'm doing something wrong.
- AdamJacobMuller 6y agoYou can't consider all bit-flip possibilities, you have to consider only those which result in valid domain names. Flipping a bit which results in a w becoming a / will never result in a valid domain name, for example. Your bit math here is wrong (not sure why). > "windo7s", but "w" is 01111000 and "7" is 0000111 7 is 055 is 0011,0111 w is 119 is 0111,0111 2nd bit is flipped
- cmeacham98 6y ago> 199,180 NTP Client connections from 626 unique IP addresses This seems like an abnormally high connections/IP, even if we assume some of the IPs represent multiple clients. Perhaps it's because of retrying as the author does not seem to have sent NTP replies back?
- NobodyNada 6y agoThat's over 14 days, so it averages to just under 1 request per IP per hour. That seems reasonable for an NTP server. What seems stranger to me is the incorrect clock settings on 30% of those computers. Why do they all think it's the end of September (even though the years are drastically different)?
- cmeacham98 6y ago> Why do they all think it's the end of September I suspect this is just because the author is sorting the text, and the days at the end of September are lexicographically last given that date formatting.
- fomine3 6y agoThat's why ISO-8601 should be default.
- mminer237 6y agoBut to have your computer bitflip 300 times in a couple weeks is impossible. Either the address is cached incorrectly for a long time or it's just a typo in a config file.
- bibinou 6y agohttps://news.ycombinator.com/item?id=26341576 https://news.ycombinator.com/item?id=26341576
- nucleardog 6y agoGonna wager some sort of cheap IoT/embedded device inappropriately abusing Microsoft’s NTP server with a typo in the configuration.
- vermilingua 6y agoThe buried lede here is what's going on with Baidu. Presumably the initial erroneous request was typed into a browser, does Baidu operate a browser in China? Do they operate a portion of the backbone network infrastructure, and are inspecting traffic? If not, how could they possibly have identified this as a target for crawling, unless perhaps they are being fed traffic by the Great Firewall?
- erk__ 6y agoI don't think they operate a browser anymore. My guess at how this happend was that some user tried to open the site, it failed and the copied and pasted the url into Baidu search which then crawled it, and probably also corrected the misspelling.
- _trampeltier 6y agoI did hear in a talk, where they did this with (as far I remember) google.com, a lot of such wrong traffic came from china too.
- kalleboo 6y agoEven if they don't have a browser they could have a browser extension edit: it looks like they also have antivirus software which could be scanning urls
- deleted 6y ago[deleted]
- JdeBP 6y agoThat's easy enough. There are WWW pages that contain "time.wiodows.com". I turned up a couple with Bing, in examples of how to use the ntpdate program, and there are no doubt more, including ones where this is hyperlinked by some "smart" program. No need for a nefarious explanation when a WWW spider found this on a WWW page and decided to crawl it will do just as well. (-:
- banana_giraffe 6y agoEven if they're not hyperlinked, at this point, I wouldn't be surprised to learn of a crawler looking for FQDNs and things that just generally look like URLs in text to crawl into.
- axaxs 6y agoOne rather insidious one I'd never considered prior was that lowercase n is one bit from '.'. So you can also bitsquat on things like, say, wwwngoogle.com or mailngoogle.com. A researcher brought this to my attention years ago with a set of domains in particular I won't name. What was most interesting to me is just how frequent bit errors must happen. According to the research, they'd basically received thousands of emails destined for the correct domain. Really makes you think.
- benjojo12 6y agoFor this bit flip to work it would have to happen before it was handed down to the actual resolver, since on the wire this flip would just cause a invalid parse of the DNS label
- axaxs 6y agoThis "attack" is against the ordinary user, so yeah is before or at the time of the dns query. I'd expect(probably incorrectly) for the server side stuff like recursive resolvers to have ECC. So imagine you are sending a mail to jim@mail.example.com. You see it in the address field as correct. You click send, and your client resolves mailnexample.com, gets an address, and delivers it, while you are none the wiser. This is particularly bad for third level domains, which are more common than you'd expect.
- Cthulhu_ 6y agoReminds me of a former colleague of mine who was one of the principal developers behind an Android app, where they could really go to town on making it crash free, since Android offers a phone home function when a crash occurs. At some point, he made the observation that 1-2% of crashes occur not because of a programmer error or anything, but "chance"; bit flips and the like, in either the app's memory or the phone's services. So while on an individual basis it's rare, and in practice nobody will really notice an issue, statistically bit flips are significant enough to need attention.
- sumtechguy 6y ago
- knorker 6y agoOh snap, this was news to MSFT? How did they not register bitflips of windows.com and microsoft.com? I think I checked this like 10 years ago, and Google had. (well, except the infinite set of subdomains where a dot and an n are one bit away) And this is why ECC RAM should obviously be the default.
- mschuster91 6y ago> And this is why ECC RAM should obviously be the default. For routers and other hardware along the line this would (probably) be too latency-sensitive.
- Filligree 6y agoECC RAM is no slower than regular RAM. At least, it doesn't have to be. The overlap between overclocked, XMP'd memory and ECC is a null set, but that's not due to physics.
- jdsully 6y agoIt partially is, the biggest issue with parallel busses like that of DRAM is skew between the bit lanes. You need the electrical pulses to physically arrive at the same time. It's more difficult to layout 71 bits of exactly equal length than 64.
- hanniabu 6y agoSince you have experience, maybe there's something you can help explain with what was mentioned: > In fact, out of the 32 valid domain names that are 1-bitflip away from windows.com "windows" is 7 characters long so how is there 32 1-bitflip combinations? Also one of the ones mentioned was "windo7s", but "w" is 01111000 and "7" is 0000111, which isn't a single bit flip away unless I'm doing something wrong.
- jobigoud 6y agoIf we use ASCII 7-bit char codes, 'w' is 0111 0111, and '7' is 0011 0111. 7 characters of 7 bits each gives a grand total of 49 flippable positions.
- FDSGSG 6y ago>X-Forwarded-For that attempts to make the request appear as if it originated from an IP belonging to the US Department of Defense. Networking newbies always get spooked by this https://blog.erratasec.com/2013/12/dod-address-space-its-not-conspiracy.html https://blog.erratasec.com/2013/12/dod-address-space-its-not... Hundreds of ISPs out there utilizing DoD space for their internal addresses.
- Sebb767 6y agoInteresting link! > This sort of thing happens a lot. I (or others I trust) have seen 1.0.0.0/24, 22.0.0.0/24, and other instances of 30.0.0.0/24 used this way. That usage of 1.0.0.0/24 probably did not age well
- bibinou 6y agohttps://blog.cloudflare.com/fixing-reachability-to-1-1-1-1-globally/ https://blog.cloudflare.com/fixing-reachability-to-1-1-1-1-g...
- rambojazz 6y agoOh goodness! After domain squatting, one more squatting to think about! Do I have to worry about these things? How likely is it that a solar flare modifies a computer memory right when typing a domain?
- fogihujy 6y agoThe likelihood of your computer experiencing a bit flip at the wrong time is microscopic. The likelihood that some computer, somewhere on the planet at any time? Much higher.
- zlynx 6y agoIt is far more likely that a DRAM chip will start going bad over time. Unlike solar flares this will definitely cause you problems. Over 25 years I have experienced this in two different computers. Unless you live at high altitude. When I lived at 7,200 feet in the mountains of Colorado my ECC system reported bit errors every month. Anyone using laptops while in flight should be scared.
- fomine3 6y agoOr if you live untrustworthy country with nuclear. https://www.jakepoz.com/debugging-behind-the-iron-curtain/ https://www.jakepoz.com/debugging-behind-the-iron-curtain/
- ay 6y agoDoD address range is not so mysterious: it’s 11.0.0.0/8, and it’s not been seen on the internet. So it is extremely tempting to take one’s 10.0.0.0/8 and turn it into 10.0.0.0/7. I would bet this is what is going on there - a large network who decided to take a shortcut with addressing, no evilz haxxorz.
- chokeartist 6y agoAgreed. I've seen people use assigned (RIR) but not announced (BGP) IP space for years in various ways. Squatting on 11/8 is common to the uneducated.
- nobrains 6y agoAnd how many of these would be typos and not bit flips caused by cosmic rays?
- statstutor 6y agoYou could quite easily test that, by comparing bit-flipped domains to keyboard-neighbour domains. Or alternatively, just by looking at the distribution of hits to bit-flipped domains (which should be broadly uniform; typos will be non-uniform).
- gsich 6y agoThe NTP conclusion is wrong. chrony also uses randomized transmit timestamps: Transmit Timestamp: Feb 2, 2045 15:47:48.317625828 UTC As per [0] this is a security feature: [0] https://chrony.tuxfamily.org/comparison.html https://chrony.tuxfamily.org/comparison.html
- mywacaday 6y agoMcAfee is flagging site as follows URL: https://remyhax.xyz/posts/bitsquatting-windows/ https://remyhax.xyz/posts/bitsquatting-windows/ URL Categories: Malicious Sites Reputation: High Risk
- abrookewood 6y agoI had McAfee flag a restaurant's website because they mentioned alcohol (i.e included their wine menu). I went to the hassle of submitting a request to change the category ... and it was rejected!
- deleted 6y ago[deleted]
- wooptoo 6y agoSomewhat related: I run an http server on the local network for various services. Due to the large number of bogus requests I set up a honeypot vhost which responds only to requests sent without a Host header, i.e. received directly on the IP address. It also logs these requests separately. It's fun to check the logs once in a while and see all sorts of exploit attempts. Wordpress and PHP seem to attract a lot of attention.
- Guest42 6y agoCan you elaborate a bit on how you set things up and introduced some security?
- wooptoo 6y agoAuthorised parties have prior knowledge of the subdomains where the apps reside. Everyone else hitting the IPs directly (presumably coming from mass IP scans) will be met with a honeypot vhost returning nothing. An example can be found in the nginx manual with the catch-all approach: https://nginx.org/en/docs/http/server_names.html#miscellaneous_names https://nginx.org/en/docs/http/server_names.html#miscellaneo...
- Guest42 6y agoFantastic, didn’t know that was possible
- jffry 6y agoAs a fun exercise sometime, spin up any cheap EC2 instance in AWS, set up an HTTP server listening on port 80 and 443, and watch your SSH and HTTP logs. The last time I did this I had random SSH and HTTP requests rolling in within minutes.
- logshipper 6y agoI recently interned in cloud security for a mid-sized firm. In my first week, I spun up a free-tier EC2 for some testing (Only port 22 was open) and soon enough, the logs were full of port scans and unauthorized ssh attempts. It is only then I realized the scale at which malicious parties operate. Suffice it to say, I was very careful with my filters after that incident.
- jyr0s 6y agoaren't Ethernet frames CRC'd? Are there other checksums down the call stack, or up the stack at the other end, that would reject such bit flips in the raw data?
- quenix 6y agoYes, Ethernet frames are CRC'd but some (most?) memory isn't. The web address is bit-flipped in memory, and then the network stack generates a valid Ethernet frame using the already corrupted address.
- nneonneo 6y agoThe “US DoD” IP could simply be a mobile network operator’s internal IP address leaking via the XFF header. Mobile network operators are known to use public but unadvertised IP ranges such as 25.0.0.0/8 (UK MoD: https://blog.wireshark.org/2010/04/t-mobile-clever-or-insane/ https://blog.wireshark.org/2010/04/t-mobile-clever-or-insane...) for their internal networks in order to avoid clashes with actual private IPs. For example, by using a “public” IP address, any private IP address requests from a client will route through e.g. WiFi instead of through the cell network. It would not surprise me if a Chinese mobile network operator was using chunks of unadvertised US DoD IP address for the same purpose.
- 0898 6y agoWha? Can somebody explain to a non-programmer now one character can "flip" in a computer and become another one? Is this quite common?
- astrea 6y agoRAM (the temporary memory where your operating system, programs, etc are stored) stores bits as charge in a capacitor. Now this is where my understanding falls apart, so I'm going to take an educated guess and hope someone smarter corrects me: Random energy from thermal heat or stray cosmic particles can cause these bits to leak from the capacitor or for an extra charge be thrown into the wire as the data gets transmitted.
- Retric 6y agoIt’s extremely common over time, but rare for any one calculation. This is why ECC memory is so useful: https://en.wikipedia.org/wiki/RAM_parity https://en.wikipedia.org/wiki/RAM_parity
- oxymoron 6y agoSemi-related: I remember a story from HN a few years ago where someone started experiencing crashes and tracked it down to a single flipped bit in memory which went away when he purged his page cache so the binary was reloaded from disk. Does anyone happen to have a link to it?
- whelming_wave 6y agoI don't remember it on HN, but this is prodding my memory about an article where the specific executable that was corrupted was `bc' on Linux, if that helps any other readers track it down. I think it specifically broke subtraction or something?
- HomeDeLaPot 6y agoI remember it too! This one? https://blogs.oracle.com/linux/attack-of-the-cosmic-rays-v2 https://blogs.oracle.com/linux/attack-of-the-cosmic-rays-v2
- oxymoron 6y agoThat’s the one! Thank you!
- WarOnPrivacy 6y agoI wish I had kids so geeky that this was a regular bedtime story.
- djrogers 6y agoThe behavior seen here seems to indicate typos more than bit flipping - ex, look at the NTP requests: it works out to roughly 1 request/hr from the ~600 IPs that are hitting them, that's not an in-memory bit-flip.
- londons_explore 6y agoCertain in memory or on disk bit flips would make it use the wrong domain repeatedly until rebooted, or even until the system was reinstalled. Having said that, I suspect that if these were investigated in detail you would find software bugs or typos to be the majority. Simple things like a race condition when suspending to RAM could flip a few bits occasionally if the RAM isn't correctly refreshed.
- walrus01 6y agothe use of the department of defense IP there is most likely because it's a ISP using one of the DoD's ipv4 /8 blocks internally. There's more than a few (and not just all in China) that have done that, in an attempt to shovel back the tide of needing to fully migrate to ipv6, or due to lack of other ipv4 resources for unique customer numbering.