9 ms·
Possible BGP hijack
- cjbprime 5y agoELI5 "in Paw Patrol terms" from Stamos: https://twitter.com/alexstamos/status/1499873636500475904 https://twitter.com/alexstamos/status/1499873636500475904 It might be a false positive: https://twitter.com/mdhardeman/status/1499877247167209480 https://twitter.com/mdhardeman/status/1499877247167209480
- randomhodler84 5y agoWtf is mayor goodway? And why is he in this confusing analogy?
- umvi 5y agoMayor Goodway is the mayor of fake-San-Francisco ("Adventure Bay") in the kids' show "Paw Patrol". Also, she is a woman, so I'm not sure why Mayor Goodway is referred to as "he"
- tptacek 5y agoIt's a joke; somebody asked for a Paw Patrol analogy. It's not actually an explainer, and wasn't intended to be taken as such.
- secalex 5y ago"Paw Patrol Explainers Considered Harmful" In this thread, I will deconstruct... (1/49)
- randomhodler84 5y ago
- ehPReth 5y agoYou were new at one point too.
- serf 5y agoI see validity on both sides of the table. Yeah, someone new and experienced should have all the effort possible put into them by others trying to catch them up.. on the other hand the whole 'ELI5' phenomenon really has no place in niches that really have no point to be generalized for the average population. 'ELI5' breaks down when comprehension of multiple topics is required for elucidation; i.e.: a layman's explanation of quantum chromodynamics requires many other base level comprehensions before it can be tidily explained. The 'ELI5' thing is cute, and it has a place -- but it shouldn't be generalized to all education across the board.
- Cottages 5y agoI feel this way whenever I have to explain that, no, sex is not a binary related to XX or XY, there's lots of genetic variations (many of which don't fall neatly into male or female). There's lots of stuff like that across a wide range of disciplines -- computer science, biology, sociology, physics, economics, etc.
- randomhodler84 5y agoFor sure. Life is beautiful and nuanced. Anything significant is complex, and quantizing a spectrum, or at worst, making it monochromatic, takes something from its beauty.
- samstave 5y agoOH MAH GAWD PATRICK (I know youre not patrick, I made that joke almost a decade ago!) I just haven't seen you 'round these parts recently.... May you please provide a link to your analysis of WTF might happen in recent-future times? I was predicting a major infra/cyber war... It seems that actions of the world have curbed that enthusiasm... However; the spectre lingers from an info/dev/ETC/sec position ; here me out: --- Aside from what we are seeing in the global political frame ; which means nothing to political aspirations on the personal level : We are seeing a MASSIVE shift on the authoritarian control to global HUMAN mobility in all : Mindshare, Finance, Tech, Social-Acceptability, etc. The RESET. is in changing the mindshare around such topics. Lets take into your realm: Cyber-Sec... --- Extrapolate 10 years. If you have not done so already, What will cyber-sec look like in 10 years? What will ID look like? What will currency access look like? What will financial channels for individuals look like? What will access to "goods and services" by those who wish to not deal with "the system" look like? What will social-mobility look like? If you are not evaluating and thinking about this, I do not trust you
- lbotos 5y agoPretty sure this is paw patrol but agreed, from the outside, it's incomprehensible. (I'm on the outside with you)
- ineedasername 5y agoI think I have a Voltron analogy somewhere that can explain the Paw Patrol one...
- deleted 5y ago[deleted]
- dsl 5y agoIt is a false positive. Both the originating and "hijacking" AS are the same Ukrainian ISP (Netgroup).
- secalex 5y agoThe advertising ASN does not share any upstream peers. So it might not be a hijack, but it is an interesting event and could be related to the conflict. Untangling ISPs that have operated in both countries or with subsidiaries is going to get messy while infrastructure is also getting destroyed.
- deleted 5y ago[deleted]
- jsizzle 5y agoIt’s VERY likely a false positive. It’s the same ISP
- drglitch 5y agoIt is quite plausible that Russia would try to take down parts of Ukraine internet given everything going on. Alternatively, could simply be someone fat-fingering things, given the insane numbers of blocks that RosKomNadzon has been putting in today (Facebook, Twitter, etc)
- nine_k 5y agoI read an article (in Russian, will link later) outlining a plan to copy current BGP tables, update them so that the Russian internal internet space is encircled with government-controlled ASes, and filter or block any outside access, while making the BGP inside Russia look synchronized with the rest of the world. Of course this applies to all BGP announcements from outside the perimeter. Not exactly a great firewall with packet inspection, but still something to prevent any possibility to access any resources except whitelisted ones, or to run a VPN to the outside. Update: the article in question, Google-translated: https://whatisyournameinsider-com.translate.goog/politika/248511?_x_tr_sl=ru&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp https://whatisyournameinsider-com.translate.goog/politika/24...
- stadium 5y agoIf Russia is preparing to up its information warfare game does this give them better defenses against inbound attacks? While letting FSB selectively allow outbound attacks?
- throwaway984393 5y agoGentle reminder: You can still generate valid TLS certificates for arbitrary domains with BGP hijack. Hide yo logins, hide yo passwords, and hide yo persistent sessions too, they hijackin' errrbudy up in here
- advisedwang 5y agoI assume the mechanism here is to hijack the DNS servers? Does DNSSEC protect against this?
- fulafel 5y agoDNSSEC could be used to protect against it, if TLS cert issuing policies were tightened by folks who mandate the minimum verification requirements for CAs, but this is not currently done. (eg Let's Encrypt supports DNS verification as one mechanism currently, but it also supports plaintext HTTP which is vulnerable to BGP hijack)
- throwaway984393 5y agoE-mail, DNS, and HTTP validation are all vulnerable (so, all the methods besides ACME). As for DNS validation, DNSSEC is opt-in; if one of the 350 different Certificate Authorities doesn't do mandatory stub validation, then the hijack still works on them. There's actually multiple attacks using BGP. You can either hijack the DNS or E-mail server's IP and spoof records, or you can hijack the IP of the target host and spoof an HTTP response. Or you could try all 3 to maximize your chances.
- bawolff 5y agoThere are non dns mechanisms as well - you can directly hijack the websites ip address instead of their dns server. In theory i think https://en.m.wikipedia.org/wiki/Resource_Public_Key_Infrastructure https://en.m.wikipedia.org/wiki/Resource_Public_Key_Infrastr... is the thing that's meant to stop this attack if everyone adopted it.
- jart 5y agoChrome doesn't support DNSSEC sadly. https://bugs.chromium.org/p/chromium/issues/detail?id=50874 https://bugs.chromium.org/p/chromium/issues/detail?id=50874
- jokoon 5y agoI noticed reddit and other big websites were somewhat slower at one point those couples of days... I live in Europe and I wonder...
- thamer 5y agoThis says the prefix being announced by two ASNs is only a /24, which is kind of narrow for a hijack? Considering the countries involved, reporting this as a hijack will inevitably lead to people assuming it is related to the current conflict.
- zamadatix 5y agoAS212463 only announces 2 /24 prefixes in total so it being only 1 isn't a big sway one way or the other. The company being the same just across the 2 countries makes it less likely to be something militarily malicious but doesn't necessarily mean it's unrelated to the current conflict.
- motohagiography 5y agoA /24 wouldn't propagate much farther than the nearest IX and immediate peers, as presumably peers have learned to aggregate and filter in the last 20 years. At face value, it really seems like a shift to backup routes. Also, state level attacker view, hijacking a route from another ASN is a bit 3rd world, as if you were a superpower, you'd have already hacked the routers in question and would just loop traffic through and MPLS tunnel to your analysis centre.
- jlgaddis 5y ago> A /24 wouldn't propagate much farther than the nearest IX and immediate peers, as presumably peers have learned to aggregate and filter in the last 20 years. ... and yet the global BGP table is absolutely full of /24s.
- samstave 5y agoIs Raleigh Mann not still the canon state of truth on BGP?
- deleted 5y ago[deleted]
- mmaunder 5y agoPrefix 31.148.149.0/24 is normally announced by AS212463 HE shows belongs to https://dataline.ua/en/ https://dataline.ua/en/ which is a Ukrainian company. https://bgp.he.net/AS35297 https://bgp.he.net/AS35297 Is now being announced by AS35004 which HE shows is Ukrainian hosting provider https://netgroup.ua/ https://netgroup.ua/ But the "Country of origin" of the AS is listed as Russian, which is perhaps where the confusion comes from. https://bgp.he.net/AS35004 https://bgp.he.net/AS35004 About 95% of new AS35004's traffic goes through this peer: (which is Ukrainian) https://bgp.he.net/AS13249 https://bgp.he.net/AS13249 And this peer: (which is Ukrainian) https://bgp.he.net/AS3326 https://bgp.he.net/AS3326 Both of which Peer with Cogent. What is interesting is that Cogent today decided to cut service to Russia. https://www.reuters.com/technology/us-firm-cogent-cutting-internet-service-russia-2022-03-04/ https://www.reuters.com/technology/us-firm-cogent-cutting-in... If I was an ISP had networks from UA and RU and my Cogent peering was removed from Russia, I might move some of my traffic through my partner in Ukraine, who does have a peering arrangement with Cogent. I haven't confirmed that is what happened, but you would see this kind of shift I think if they did that. I'm a security guy and not a CCIE so perhaps a Cisco engineer here can weigh in.
- 0x0000000 5y ago10 year CCIE and ex-Cisco engineer here: I think you nailed it.
- jlgaddis 5y agoWhat's interesting (to me, at least) is that there's an (signed) ROA for 31.148.149/24 and AS212463 is listed (IRR) as a valid origin AS -- AS35004 isn't. All things considered, though, I'd find an explanation of "yeah, didn't have time to update the route objects yet" to be completely acceptable. Same situation with 95.47.59/24, by the way. (I let my Cisco certs lapse a decade or so ago, although I've certainly originated a prefix or two over the years.)
- theginger 5y agoIn simple terms you are saying this is probably not a hijack?