11 ms·
Someone was breaking into Orange Spain RIPE account (and break their /12)
- kinow 3y agoI was affected by that attack. After lunch here in Barcelona several sites started to time out on Firefox: GitHub, Twitter, Hacker News, Canva, DuckDuckGo. While others like Reddit, Google, YouTube kept working. Found via Twitter that others had already tried changing DNS servers, and then did a tracepath and found that I couldn't reach the resolved IP's. Thought it would have been a misconfiguration of Orange. Then on Twitter (accessed via Orange mobile, which funnily worked fine -- probably a different network?) I found a thread of the people in Spain complaining about it, where someone later replied with links to the RIPE account take-over tweet. Took about 2-4 hours for the service to be fixed. Haven't fixed any other issues so far. One of the articles pointed that it could have been due to someone that was not using 2FA, but there were no sources in that article. EDIT: the article mentioned above https://bandaancha.eu/articulos/secuestran-cuenta-ripe-orange-espana-10796 https://bandaancha.eu/articulos/secuestran-cuenta-ripe-orang...
- londons_explore 3y agoWhat evil could one do with this?
- WarOnPrivacy 3y agoSome years back, Russia hijacked a BGP belonging to a major transit provider. For a few hours, international traffic was rerouted thru Russian networks where it could be cloned (like the NSA does in the states) and examined. They could have been after something specific in the traffic but my unqualified guess is that it was a test or they were showing off.
- ethbr1 3y agoCurious to speculate about. If you could temporarily redirect BGP at an arbitrary time, at diplomatic risk, what would be the best use of that? Surely OpenNet/ClassNet/NIPRNet/SIPRNet/GWAN/JWICS aren't accepting BGP updates, where they even touch public network infrastructure. And I can't think of anything outside those huge spheres that would be worth burning a capability like that on a lark. Maybe bulk sensitive data transfer? I.e. some site-to-site backup? Or you're just looking at the metadata of where-to-where, with the goal of finding future targets.
- bawolff 3y ago> Surely OpenNet/ClassNet/NIPRNet/SIPRNet/GWAN/JWICS aren't accepting BGP updates, where they even touch public network infrastructure. If i understand, the article is not so much a typical bgp hijack but the attacker gaining control of their account that controls routing. Seems like private networks would be just as vulnerable to that.
- ethbr1 3y agoIn the case of the article / Orange, possibly. Though I'd hope that Orange doesn't provide network management services for the Spanish military! Some things are better kept in-house. Less familiar with how European sensitive networks are architected.
- Jhsto 3y ago> Less familiar with how European sensitive networks are architected. Some governments have physical tunnel networks to move people who matter around. Computer networks follow pretty much without a loss of generality.
- anthk 3y agoIndeed, RedIris in Spain, since late 80's or maybe early 90's, can't remember.
- anthk 3y agoAs they stated, European gov networks (plus military and universities OFC) had and still have their private backbone. In Spain, RedIris was for scientific research, universities and such. IDK about the rest, but for sure they'd have a similar approach.
- WarOnPrivacy 3y agoI went back and looked up the event. Rostelecom has been behind a few of these. I might be conflating two of them. In 2017, Rostelecom grabbed financial & other network data for a few minutes. https://www.thousandeyes.com/blog/rostelecom-route-leak-targets-ecommerce-services https://www.thousandeyes.com/blog/rostelecom-route-leak-targ... In 2020 Rostelecom announced lots of networks they didn't own and got that traffic for an hour. Early analysis felt it was accidental. Not sure about later analysis. https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/ https://www.zdnet.com/article/russian-telco-hijacks-internet... https://news.ycombinator.com/item?id=22789754 https://news.ycombinator.com/item?id=22789754 But 2 months ago, Rostelecom grabbed a chunk of Apple's network (which I missed) https://cybernews.com/apple-network-traffic-went-through-russia-for-12-hours/ https://cybernews.com/apple-network-traffic-went-through-rus...
- bawolff 3y agoEncryption on higher level protocols (https) can do a lot to reduce potential impact. Big impacts that come to mind (depending on what is being hijacked): - dos attack - pasive eavesdropping (not of encrypted contents, but who is connecting to who) - hijacking plain http - hijacking things like ssh where nobody pays attention to the mitm warnings - potentially creating a new tls certificate to further do a later attack
- midasuni 3y agoHijack the ip or dns entry and you break https as it’s trivial to get a new certificate and prove ownership of the DNS address adult the time.
- ethbr1 3y agoBut then you show up on certificate transparency logs pretty quickly, no?
- tialaramex 3y agoWell, the new certificate shows up, but so what? CT logs aren't like "Barry Shitpeas got a certificate for hugecorp.example" they just tell you what was issued, not why, not who in any useful sense was issued it, and they take up to 24 hours to do that. What is the overlap between the set of people who think "pass1234" is a good password and the set of people who have great oversight of their cert issuance and would flag unexpected issuances ? I'd expect it to be approximately empty.
- ethbr1 3y agoPresumably the site owner would be the one monitoring CT. If they see there's a rogue certificate, they can take steps to get it revoked.
- CaliforniaKarl 3y ago> … they just tell you what was issued, not why, not who in any useful sense was issued it … They give you the certificate, which contains the issuer's CPS. If it's an issuer that you (the domain owner) don't recognize, you have at least a starting point for reaching out. > … and they take up to 24 hours to do that. Indeed, the Maximum Merge Delay is 24 hours. But in practice, by monitoring multiple CT logs, it takes just a minute from successful issuance to having the certificate show up in at least one CT log (see https://utcc.utoronto.ca/~cks/space/blog/web/WebProbeSpeedNewTLSCertificate https://utcc.utoronto.ca/~cks/space/blog/web/WebProbeSpeedNe...).
- SOLAR_FIELDS 3y agoFor those like myself that are somewhat unfamiliar with what RIPE is: RIPE is the European equivalent of ARIN (the North American regional authority of ISP addressing matters). They are sort of like the postal/zoning agents of the internet in that they oversee the distribution and management of IP address blocks. ISPs like Orange Spain have a RIPE account that they use manage their IP allocations, which is what was compromised.
- tialaramex 3y agoThe technical term for these is RIRs. Regional Internet Registries. There are five of them, ARIN (North America), APNIC (Asia Pacific), RIPE (Europe), AFRINIC (Africa) and LACNIC (Latin America). The RIRs are delegated the numbers from IANA, and they in turn delegate numbers to LIRs, Local Internet Registries, such as an ISP or a maybe a large organisation which has vertically incorporated that functionality. The RIRs represent, and are paid for by, the LIRs in their region and so to some extent they reflect local consensus, local culture, etc. This means in some sense RIPE's security policies reflect what European ISPs and similar wanted, for good or ill.
- actionscripted 3y ago> This means in some sense RIPE's security policies reflect what European ISPs and similar wanted, for good or ill. Traditional routing has always been very, very open. Like a club where anyone is welcome and if new folks mess stuff up it just gets fixed. Several IRRs used to allow RPSL changes by email to their systems with only maintainer auth and no verification of route ownership (e.g. you register with the IRR, then publish Google routes). It’s all getting hardened nowadays with things like no more email, layers of verification, RPKI, etc. It’s not necessarily what folks want but how this stuff had traditionally been handled. Thankfully it’s all changing because of events like this.
- greyface- 3y agoAllegedly, Orange Spain's RIPE password was "ripeadmin", with no 2FA: https://twitter.com/Ms_Snow_OwO/status/1742666456058470739 https://twitter.com/Ms_Snow_OwO/status/1742666456058470739
- justinclift 3y agohttps://nitter.net/Ms_Snow_OwO/status/1742666456058470739 https://nitter.net/Ms_Snow_OwO/status/1742666456058470739
- zamadatix 3y agoThat's pretty loose protection on 10s of millions of dollars of asset.
- mixdup 3y agoif it's true, it's ridiculous BUT the cost is just the cost of downtime. is anyone under the impression that they'd actually be out these IP addresses permanently? obviously RIPE would fix the issue and get the IPs returned
- zamadatix 3y agoI didn't mention cost for that reason. It's just silly to put so much into assets and then not even put basic protections on them being accessed by others instead.
- gbil 3y agoYes and no, while RIPE can help they can only up to a point. For example, the assets are transferred to someone , up to that point RIPE can help but if another transaction has followed then sorry but they can't do much
- kortilla 3y agoThis isn’t the blockchain. All of that can be easily reversed
- Tiberium 3y agoThe title was confusing at first, with "was breaking into" I thought the attacker didn't succeed, but they did. Can the title be changed to something like "Someone hacked Orange Spain's RIPE account and broke their /12"?
- 0xbadcafebee 3y agoThis is one of several attacks that can be used to generate valid TLS certificates for domains you don't own. There are mitigations but they can all be defeated. This will persist until there is reform among internet standards groups, but they are controlled by the browser market, and they aren't responsible for generating the certs, so it's one of those "nobody is responsible so it will never be fixed" deals.
- tialaramex 3y agoWhat "reform" do you think would help? The problem here appears to be that the victim didn't do even a halfway decent job of protecting their RIPE account. RIPE offers TOTP. TOTP is hardly the best possible security, because it can be phished, but assuming the people using it are competent (and why are your networking team incompetent?) that ought to be adequate. It seems as though Orange didn't bother to enable TOTP and indeed didn't even set a decent password.
- bawolff 3y agoNobody does this, but in theory dns-sec combined with a CAA record set to nothing would mitigate this in a way that can't be defeated, right? In principle key pinning would be the counter measure, but that was so problematic it was removed from browsers. I think chrome still does static key pinning for their own domain, and many mobile apps do key pinning, so its not entirely dead, just mostly.
- CaliforniaKarl 3y agoPotentially yes: Site owners could set a CAA record like… nocerts.example.com CAA 0 issue ";" … telling CAs that they shouldn't issue certs for `nocerts.example.com` at all. That being said, it would make things difficult when it's time to do a cert renewal: You'd have to update the CAA record, wait for it to propagate, do the renewal, and then set it back. And that's a window that could be exploited. What could work is CAA, along with RFC 8657: Certification Authority Authorization (CAA) Record Extensions for Account URI and Automatic Certificate Management Environment (ACME) Method Binding (https://datatracker.ietf.org/doc/html/rfc8657 https://datatracker.ietf.org/doc/html/rfc8657). RFC 8657 extends the CAA record to say "Only this specific CA account may request certs for this domain" and/or "Only this specific validation method may be used when requesting certs for this domain".
- heads 3y agoMaliciously changing a RIPE allocation would be like going into a pub and moving Geoff’s drink to one side so you and your mate can take his and Frank’s spot at the bar. While you may physically succeed at this, you will also find you don’t get served and you do get thrown out and barred. I’ve always liked the professional level of collusion that makes the Internet work. One day it will all go wrong and we’ll have to set up something democratic, but until then the technocracy works well.
- Lovesong 3y agoWe were affected by the downtime, suddenly our VPNs went down and we started troubleshooting if it was a switch sudden reboot, a physical problem, anything. Odd for some of our VPNs to randomly shut down rejecting all traffic but just at the endpoint. Then we started having some very specific problems with just some FTP addresses and couldn't figure out what was happening. Until our CIO went to the bathroom and came back saying "Hey, these websites aren't working from our WIFI network but they're working fine from mobile data? Could it be a navigation problem from Orange?" Then we realized it.