9 ms·
How to get the whole planet to send abuse complaints to your best friends
- jmuguy 2y agoIt seems like systems shouldn't report abuse (at least automatically) for single packet, no round trip, requests unless its reaching denial of service levels of traffic (and maybe these are). Like in particular for SSH there's no way thats even a valid connection attempt until some sort of handshake has occurred.
- Avamander 2y agoSometimes that's all the abuse you'll see though, with for example port scans.
- boring_twenties 2y agoWell the obvious answer there is that port scans shouldn't be considered abuse absent other factors like rising to the level of a DoS.
- fullspectrumdev 2y agoExactly this. A single SYN or TCP connection doesn’t constitute abuse. Unfortunately many people seem to think otherwise and will spaff abuse reports over an errant SYN packet
- Avamander 2y agoRecon is the first step in an attack chain. So just ignoring it would let a lot of criminals operate without constraints.
- EasyMark 2y agoIf you scan a bunch of my ports and you aren’t on my LAN then your IP gets banned (ignored) for a week.
- Dylan16807 2y agoGo for it. But I don't see the relevance to the comment you replied to?
- franga2000 2y agoBut since anyone can submit an abuse complaint, maybe server providers should actually check the abuse reports before triggering the "respond in 2 days or we suspend your server" or similar measure of their ToS. I've had my main server thrown offline by a bogus abuse report claiming that they received an over 1Gbps DoS attack from my IP even though my server only has a 400 Mbps cap. Had a human actually read the report, they would've seen it was impossible and wouldn't have had to spend 2 days arguing with phone support on my holiday.
- ziddoap 2y agoThis type of issue can be incredibly annoying to deal with, because the legitimate answer to the abuse report ("someone is spoofing my IP, it isn't me, and the machine is not compromised") is the exact same excuse that a malicious actor would provide. Then, as noted in the article, you're trying to prove a negative to someone who doesn't really care at all, which is borderline impossible.
- dataflow 2y ago> the legitimate answer to the abuse report ("someone is spoofing my IP, it isn't me, and the machine is not compromised") is the exact same excuse that a malicious actor would provide. The legitimate answer would include some sort of real-world attestation about you from a trusted third party. Probably the very least, some evidence of your identity and jurisdiction. Maybe including a video call or something. Not just you anonymously claiming you're a good guy over the internet and expecting to be believed.
- preciousoo 2y agoHetzner (if they keep logs) should be able to verify if a user has been sending arbitrary packets out on port 22 very trivially
- Ardren 2y agoJust what type of logs do you expect Hetzner to keep?
- preciousoo 2y agoAt minimum? In/outbound traffic
- qiqitori 2y agoCause that's probably just a TB of logs per short unit of time.
- mrbluecoat 2y ago> The internet was broken 25 years ago and is still broken 25 years later. Spoofed source IP addresses should not still be a problem in 2024, but the larger internet community seems completely unwilling to enforce any kind of rules or baseline security that would make the internet safer for everyone. Same with spoofed MAC addresses, email addresses, ARP messages, Neighbor Discovery, MitM TLS certificates ... It's amazing anything works anymore :D
- Asmod4n 2y agoIt’s quite sad the only mail server out there which checks if you are allowed to use a email address is exchange. With all others you can set the from: header however you like.
- salawat 2y agoWho cares whether it's the MTA that does it or a collection of daemons invoked by the MTA? Just get things configured correctly, and you should be gold. Now as far as every other mail operator setting up their stuff right such that From spoofing is no longer feasible, well... Can't help ya there. I don't run my email to make money, so the incentive to adopt pathological configs for the sake of maximizing the number of users/Domains who can send from one IP ain't there.
- colechristensen 2y agoThe thing is, obviously, that the Internet isn't broken, it has incredible utility and reliability. If it was designed and operated to be perfect, then it would likely be massively broken quite often. It is the tolerance for mild brokenness that has contributed significantly to its robustness and utility. That isn't an argument for not improving things though, just a warning against perfection, if you chase it then you're liable to make really big mistakes that ruin everything.
- kombookcha 2y agoRetaining functionality even in the face of mild-to-moderate borkedness is sorta the inciting goal for even making it in the first place, way back in the cold war days. Building on top of "How do we make a communications network that can handle a bunch of nukes" sets you up for a very resilient baseline :)
- ahofmann 2y agoHow difficult would it be to highjack this attack by sending these packages to everyone, so that providers like hetzner would get swamped with abuse emails? This way the attack would not work anymore. Either the honeypots would stop sending abuse emails, or the providers would filter those out.
- dataflow 2y agoProbably easy, as long as you don't mind being on trial for violating something like CFAA.
- preciousoo 2y agoOr someone would figure out how to find who’s behind the spoofed requests, as those orgs have the resources to do so
- Ekaros 2y agoWhy not make ISPs responsible for blocking any such traffic. In the end it must originate from someone's network. And really they also should know who their peering partners are and what traffic should be allowed from there.
- salawat 2y agoWhich do you prefer? Internet where you send a packet over the wire and the network takes it and delivers it per RFC. Basically OG Internet. Network of networks of more or less trusted peers. Or Internet where you need to requisition every connection/circuit be provisined before it is routed, which includes explaining why you need the service, and where any provider in the chain will deny you transit by default? You now must forge an intimate relationship with every middle box between you and the other endpoint. This process must be repeated by everyone on the network. Just operating as a middle box for someone else is now fraught with legal liability; as anything one of your transit's end up doing, you are now considered complicit in. Both of these architectures of an Internet are equally valid and functional. The society that uses them however is completely different. I prefer the former, warts and all, and lack of throat to throttle short of the asshat running the software on the other end, over the latter, because with the former at least, we're not creating power nexii to attract asshats to NetOps positions. With the latter setup, sure, your spam problem has an ostensibly way higher barrier to entry in the form of having to create human trust networks, but the accretion of social power distinctly changes the culture of the net sector, attracting a type of personality that should never, ever be trusted to be given a yay/nay authority over other folks access to a network.
- preciousoo 2y agoThis is pretty clever
- cobbal 2y agoIt's a similar problem to swatting. It relies on authorities taking severe action against an unverified source of problems. I suppose a difference is that they use unaffiliated parties to send the complaint, instead of contacting the authority directly.
- wizzwizz4 2y agoThere's no in-band solution to this problem, but out-of-band solutions might exist! For example: (1) Notify the destination ISP that you're receiving backscatter. (2) That ISP checks where the packets are coming from, and notifies that ISP. (3) Repeat step 2 until source is found. (4) Quarantine that part of the network until it behaves better. At the end of the day, the internet is people.
- salawat 2y agoPeople are sometimes shocked to learn that the Internet as a whole works because there is a subset of humanity that really, really likes overseeing the most over-the-top pipe game in existence.
- wizzwizz4 2y agoSee also: https://news.ycombinator.com/item?id=41985920 https://news.ycombinator.com/item?id=41985920
- remram 2y agoYour steps 2&3 require a lot of people to put in work for free to solve someone else's problem.
- wizzwizz4 2y agoBut they're not arbitrarily-selected people: they're network administrators. Somebody spoofing IP addresses to the point of abuse reports is practically a personal insult to some of them. (Obligatory: https://xkcd.com/705/ https://xkcd.com/705/)
- remram 2y agoAbuse reports that are not directed at them...
- Habgdnv 2y agoThis is nothing new. A few years back, I implemented a very basic firewall rule: if I received a TCP packet with SYN=1 and ACK=0 to destination port 22, the source IP would get blacklisted for a day. But then I started getting complaints about certain sites and services not working. It turned out that every few days, I'd receive such packets from IPs like 8.8.8.8 or 1.1.1.1, as well as from Steam, Roblox, Microsoft, and all kinds of popular servers—Facebook, Instagram, and various chat services. Of course, these were all spoofed packets, which eventually led me to adjust my firewall rules to require a bit more validation. So, I can assure you this is quite common. As a personal note, I know I’m a bit of an exception for operating multiple IP addresses, but I need the flexibility to send packets with any of my source addresses through any of my ISPs. That’s critical for me, and if an ISP filters based on source, it’s a deal-breaker—I’ll switch to a different ISP.
- pixl97 2y ago>I’ll switch to a different ISP. I mean, technically those ISPs would be in violation too. You need your own ASN.
- jcalvinowens 2y ago> but I need the flexibility to send packets with any of my source addresses through any of my ISPs As someone who always enables rp_filter everywhere... I'm very curious why?
- Jerrrrrrry 2y ago>As a personal note, I know I’m a bit of an exception ...That’s critical for me, and if an ISP filters based on source, it’s a deal-breaker—I’ll switch to a different ISP. "...and obviously, Pennywise, I must spoof ingress and egress..." "Of course, Agent Bond."
- immibis 2y agoIf it's your real IP, it's not spoofing, even if you send the packet through a different ISP than the one which gave you the IP. If you think about it: if you got an IP directly from ARIN you wouldn't have to send your packets through ARIN to make them legitimate.
- JoshTriplett 2y ago> Which means, if you just find one transit provider which doesn’t do BCP38 filtering… you can send IP packets tagged with any source IP you want! And unfortunately, even though the origins of BCP38 date back to 1998… there are still network providers 25 years later that don’t implement it. What would it take to get enough network providers to start rejecting traffic from all ASes that don't implement this, so that spoofing was no longer possible?
- benlivengood 2y agoCloudflare is probably enough. They already control enough ingress that their "checking the security of your connection" could actually mean something.
- toast0 2y agoYou'd have to find some way to make network providers care. Especially 'tier 1' transit providers and other networks of unusual size. It's much easier to work on reducing reflection multipliers though, because you can scan (ipv4 anyway) for reflection vectors and yell at people that will respond with 10x the input bytes.
- deleted 2y ago[deleted]
- Rasbora 2y agoBack in the day I would scan for DrDoS reflectors in a similar way, no hosting provider wants to get reports for port scanning so the source address of the scan would belong to an innocent cloud provider with a reputable IP that reflectors would happily send UDP replies to. The cloud provider would of course get a massive influx of complaints but you would just say that you aren't doing any scanning from your server (which they would verify) and they wouldn't shut your service off. The server sending out the spoofed scan packets is undetectable so you're able to scan the entire internet repeatedly without the typical abuse issues that come with it. I'm not sure how often this happens in practice but tracing the source of a spoofed packet is possible if you can coordinate with transit providers to follow the hops back to the source. One time JPMorgan worked with Cogent to tell us to stop sending packets with their IP addresses (Cogent is one of the most spoofer friendly tier 1's on the internet btw). This is the first time I've heard of this being used to target TOR specifically which seems counterintuitive, you would think people sending out spoofed packets would be advocates of TOR. Probably just a troll, luckily providers that host TOR won't care about this type of thing.
- SSLy 2y agoCogent seems terrible in general. > Probably just a troll Or someone wanting TOR to be treated like nuclear waste, because it offends their surveillance ops.
- buildbuildbuild 2y agoThe “someone hates Tor relays” theory doesn’t sound worth the effort. This could be an entity running malicious relays, while also trying to unethically take down legitimate relays to increase the percentage of the network that they control.
- aphantastic 2y agoThis is almost certainly it. There’s a lot of head-sand-burying around here about just how easily an attacker with access to logs of a not-even-that-large segment of the nodes can gain visibility into individuals’ service access patterns.
- alwayslikethis 2y agoYeah. If you hate the tor network an easier thing to do is just to overwhelm it with traffic and degrade the service. Running some bittorrent downloads might be enough.
- immibis 2y agoThis consumes your own bandwidth though. And relay operators might coordinate and notice one address is using all the bandwidth.
- nostrademons 2y agoThis is the IP version of SWATting, patent trolls, framing an innocent person, or using DMCA takedowns to remove the competition. It's basically weaponizing abuse-protection mechanisms to instead attack a target that is disliked. Interesting that the authorities can become a weak link here and be actively weaponized by unscrupulous actors to achieve their aims, but it's not really a new phenomena.
- costco 2y agoIf they were smart and had their own relays it would also make them more likely to be selected proportional to how many other relays they took out. Looking at the number of relays and "bandwidth advertised" graphs on metrics.torproject.org it doesn't look like they've made much of a difference but it's interesting nonetheless. To me, the worst part is that "Watchdog Cyber Defense," Spamhaus, Shadowserver, or some wannabe extortion artist like UCEPROTECT can submit millions of automated reports that hosts are de facto required to listen to lest their IP space be blacklisted.
- skygazer 2y agoThis is likely a very naive question, but how did the spoofer know his IP was participating as an internal Tor node? From what vantage point can that be seen? I imagine internal Tor nodes must know to connect to each other, so it must propagate through Tor. Is the attacker also a Tor node? Is it trivial to map all Tor hosts?
- neckardt 2y agoAll public Tor relays are openly listed on Tor’s directory. You can query for relays yourself here - https://metrics.torproject.org/rs.html https://metrics.torproject.org/rs.html
- costco 2y agoTor has something called a consensus that lists all relays and their flags. Clients need this to know which relays to make a circuit with. For most clients, they select a relay labelled as a guard from this file which is where their traffic first enters Tor. Some countries realized they could just block all of these IP addresses and stop people using Tor, so there are unlisted guard nodes called bridges designed for censorship circumvention that you have to get by filling out a captcha or say sending an email.
- m463 2y agogah, I remember once when I was working at a company, and we got an email complaining "stop hacking my systems!" in the end, we had a load-balancer at .1 balancing a bunch of backend servers. the complainer would have traffic to .1 that the load balancer would receive. Thing is, old or stale connections would drop out of the load balancer mapping table, and eventually the backend server connection would not get mapped, and the guy would get traffic direct from the backend server real ip address. the traffic was actually generated by the customer, but these "unrelated" backend servers looked like they were hacking him.
- 0x_null 2y ago[flagged]
- 71bw 2y agoThe way scrolling is implemented on that page is absolutely abhorrent.
- encom 2y agoHTML frames in $CURRENT_YEAR!
- gherard5555 2y agoyou mean the 2 different panels ?
- 71bw 2y agoI mean the big margins on each side where I can't scroll the page with my mouse without having to have the cursor in front of some of the text.
- flemhans 2y agoAbuse reports are marketing messages at this point.
- stronglikedan 2y agoSite seemed to be hugged when posting this comment, so: https://archive.is/Eb7TI https://archive.is/Eb7TI
- 0x_null 2y ago[dead]
- costco 2y agoI don't understand what you're advocating for. Are you against Tor because there was a vulnerability (that has since been mitigated) which led to the deanonymization of users or are you against Tor because there was an illegal service that used it? By killing existing good relays you're making it easier for someone malicious to come in, add a bunch of relays to the network, and have those relays be more likely to be used. And it won't be a saintly do-gooder either, it'll probably be some guy trying to mitmproxy crypto exchanges to steal money. PS: The fake abuse report technique was invented like 5 years ago: https://www.theregister.com/2019/04/16/spamhaus_port_scans/ https://www.theregister.com/2019/04/16/spamhaus_port_scans/
- chaz6 2y agoThis appears to be the website of the person(s) responsible: https://r00t.monster/ https://r00t.monster/ They have posted several screenshots of discussions among people affected on various channels, including Mastodon and the official #tor-relays channel on IRC.