6 ms·
Hacking Team and a case of BGP hijacking
- diafygi 11y agoFor those who are curious, 46.166.163.0/24 (the hijacked IPs) belong to balticservers.com, which is based out of Lithuania[1]. http://wikiscan.org/plage-ip/46.166.163.0/24?submenu=whois http://wikiscan.org/plage-ip/46.166.163.0/24?submenu=whois
- rudolf0 11y agoThis is pretty crazy. I wonder how the route hijack didn't get noticed by anyone at the time, though? Or at least if someone did notice, they didn't make a fuss about it.
- gr0wln1n 11y agoThat frightended me a little to.. It seems like these things can fly by if operators don't fuck up on a major scale like recently with Malaysia(?).
- spydum 11y agoas long as they continue to route traffic out to the real destination.. who would notice latency jump from 50ms to say.. 120ms? I don't know if they did this, but you could absolutely be covert about this, and be nearly transparent to the victim.
- gr0wln1n 11y agoCan somebody explain how they got the police to help them? "You remember the RAT we sold you? Yea... That's broken because ... Help us or people might notice." If that's it.. Wow. This whole story gets more fishy by the minute.
- rurban 11y agoExactly, how can the police order an ISP to commit a crime? Why did the ISP committed the crime? Hopefully both will be charged now. The only one thing I trust here is the independence of the Italian prosecution system.
- curiousjorge 11y agoI'm not surprised, in Italy the Mafia blew up or assassinated prosecutors and lawyers threatening them. In countries where the government is not the law, anything can happen with the right sized envelops of cash.
- Laforet 11y agoSo they hijacked an entire C block because they hard coded IP addresses into their wares. Wonderful.
- acaloiar 11y agoAs someone who works in technology, but has only a cursory understanding of BGP, I find BGP's trust mechanism flabbergasting. Would anyone like to explain why it remains the preferred protocol and what improvements are in the works to mitigate the effect of these sort of hijacks?
- seiji 11y agoWould anyone like to explain why it remains the preferred protocol Legacy. BGP is a policy mechanism and sometimes the policies are either misconfigured or we can't trust hostile actors with access to wide open Internet (e.g. backwards countries null routing all of YouTube because censorship and it propagates outwards instead of inwards). In most cases, if you are talking BGP to your ISP, your ISP filters your BGP traffic to only allow specific routes you can claim ownership of to be updated. Normally, non-infrastructure-level villains can't do bad BGP things if they have responsible upstream ISPs doing filtering correctly (kill you on flapping, kill routes you shouldn't be originating, etc). But, as we've seen with ISPs not even verifying UDP source address spoofing that allows you to generate multi-hundred-gigabit DDoS attacks, many ISPs are still run by morons. BGP is also the magic behind anycast since you can intentionally duplicate any routes with no oversight (besides any upstream filtering in place). what improvements are in the works Good luck upgrading every embedded peering router in the world?
- noja 11y agoThis sounds like open SMTP relays all over again, and then came automated open relay testing and blacklisting. Is there a project like that for BGP?
- seiji 11y agoThe goal of the Internet is no central point of failure. The downside (from a regulating abuse perspective) is there's no central point of authority either. SMTP had the problem where any node on the Internet could send email for any other node on the Internet creating a game of N^2 whack-a-relay. To even get access to the core Internet BGP peering infrastructure you have to be at the upper levels of ISP connectivity to start with. So, in the US at least, that requires maybe dropping a few thousand dollars and having Official Contacts first before you're even in the game of getting your own BGP peering arrangement. If you are an intentional bad actor with bad actor connections like these awful italian hacker people then the only solution is after-the-fact punishment. The same goes if you are a country-level ISP (or any ISP part of the "core" Internet with no further upstream provider) and want to be a bad actor, then there's no oversight except when the rest of the world's network administrators comes together after seeing your malicious behavior and collectively say essentially "don't let Pakistan advertise any AS for Google properties." (alternative answer: the internet should be based on the blockchain! Imagine if every network administrator had to get on /r/InternetBackbone at the same time to agree to shut down the Internet for 20 minutes so they can all deploy a bugfix to core-internet.exe. "uh oh, we accidentally forked the Internet again.")
- acd 11y agoYou can take over other providers IP space by announcing their IPs via BGP from well connected high ranked tier ISPs, but just because you can do one thing does not mean you should exercise it. Internet was built on the premise that you can trust other organisations such as good willed universites, it was not built for a landscape of internet crime and state sponsored hackers. BGP and central certificate authorities is flawed in princicple and this sense. Its very easy to create fake certificates for big organisations if you have the power of a state. Diginotar is such an Epic fail of CA which shows exactly why you cannot trust central trust when there is state hackers at work. So you either hijack BGP, DNS or Central certificate authority then you steal peoples cookies. Since most does not use two factor authentication that is enough to take ownership of their email accounts. Once the email accounts is compromised all other accounts can be compromised through password resets.
- cft 11y agoI do not undertsand this. We recently had to change our announcement to upstream ISPs from/23 to /22 and our ISPs verified with ARIN that the entire /22 belonged to us, before changing their filters. Also, there's RADb database.
- pki 11y agoyour isps were competent maybe
- spamlord 11y agoI used to work at a spam company and we did this and similar techniques. One similar technique was we basically created our own fake ISPs, disguised as rural wireless Internet providers. Paid yearly ARIN fees, had or own /20 blocks of IP space allocated, etc. We specifically requested ip filtering completely removed from our peering connection with major upstream/backbone ISPs. They did so without question. This allowed us to source route any IP out to the Internet. Then, we would purchase large blocks of IPs (a couple of /20s a month) from Romania and Argentina. We would create GRE tunnels over to RO and route them back to the US. It's been years since I was involved so my memory of the technical details is hazy now...
- lawnchair_larry 11y agoDid anyone ever notice?
- spamlord 11y agoNot getting listed on Spamhaus was a constant battle. One time our network engineer made a huge mistake by announcing 15-20 /20 blocks registered with RIPE out of the US ASN. Spamhaus apparently automatically scans for this type of suspicious behavior and falgged like 20,000 ips. https://en.wikipedia.org/wiki/Autonomous_system_(Internet) https://en.wikipedia.org/wiki/Autonomous_system_(Internet)
- vultour 11y agoEveryone should just blackhole any traffic to and from the Aruba ISP. They have failed to maintain the trust relationship needed at high-tier ISPs and should no longer be operational.
- SnaKeZ 11y agoAruba should be boycotted for this
- based2 11y agohttp://www.bortzmeyer.org/bgp-malaisie.html http://www.bortzmeyer.org/bgp-malaisie.html