Live data from Hacker News

IP Spoofing

idea.popcount.org

21–30 of 136 posts

Re: IP Spoofing

#21
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

That would penalize a whole pile of parties that probably have nothing whatsoever to do with the spoofers. It's akin to blackholing mail from yahoo.com because there are spammers on yahoo.com.

[deleted]

Re: IP Spoofing

#22
I will never understand why some people disregard IP spoofing as a real risk. For example when I reported a vulnerability to the nginx developers (http://blog.zorinaq.com/nginx-resolver-vulns/) about their DNS stub resolver using predictable transaction IDs, they refused to consider it a vulnerability, effectively saying no one could exploit it because spoofing the IP of the DNS server can't be done on the Internet. And yet https://spoofer.caida.org/summary.php shows ~25% of network prefixes can be spoofed... sigh

Re: IP Spoofing

#23
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

That would penalize a whole pile of parties that probably have nothing whatsoever to do with the spoofers. It's akin to blackholing mail from yahoo.com because there are spammers on yahoo.com.

Isn't it more akin to blackholing mail servers that don't set up DKIM, which almost all major mail providers do these days?

Re: IP Spoofing

#24
post #15

Earlier quoted context omitted.

> They see a lot of attack traffic from tor This was debunked.

I don't believe this is actually arguable. People use tor to attempt to anonymize their (generally non-ddos) attacks. I don't believe tor can support the type of ddos the OP is talking about, of course. If you could provide the source of this debunk it'd be appreciated.

This is ridiculous. Anyone can grep their access logs for signs of obvious attacks and very quickly verify that very few, if any, of them originated from Tor exits.

Re: IP Spoofing

#25
post #8

Netflow is a great example of the dual use aspects of tech between surveillance and defense. Making Netflow data more widely available looks like it is going to be essential for defending that Internet but at the same time Netflow data can threaten the anonymity of Tor users.[0][1] [0] https://blog.torproject.org/blog/traffic-correlation-using-n... [1] https://gitweb.torproject.org/torspec.git/tree/proposals/251...

This is true, but it is a fundamental fact of the Internet, and has been since before Roger Dingledine first started presenting Tor to people at Black Hat. The major ISPs are all instrumented with Netflow, they're all collecting it, and they've all got tools (both in-house and from vendors) to analyze it.

So if you're going to try to deploy something like Tor, the table stakes are that you're secure against wide-scale Netflow instrumentation. If Netflow is an existential threat to your privacy tool, you don't have a privacy tool that is ready for deployment.

Re: IP Spoofing

#26
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

There is an excuse for not "securing" the network: disallowing spoofing is not desirable in the first place. There are legitimate uses to spoofing. What is not desirable is malware infecting user computers and using spoofing for DDoS attacks, but the ISP cannot know whether the packets were sent by malware or by a user. The proper way to solve the issue is to make secure systems that will not get infected easily by malware.

Re: IP Spoofing

#27
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

That would penalize a whole pile of parties that probably have nothing whatsoever to do with the spoofers. It's akin to blackholing mail from yahoo.com because there are spammers on yahoo.com.

Now that subscription based walled-gardens are becoming the new internet, I don't expect freedom (outsiders) to be much of a concern for society.

Re: IP Spoofing

#28
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

That would penalize a whole pile of parties that probably have nothing whatsoever to do with the spoofers. It's akin to blackholing mail from yahoo.com because there are spammers on yahoo.com.

What legitimate purpose is there for spoofing your IP address?

Re: IP Spoofing

#29
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

This sounds great in principle, but it breaks down in practice. From the article, 27% of ISPs still allow spoofing on their networks. This is mostly due to them being smaller, regional ISPs without the expertise or staff to figure out how to do this. I hear you saying "just blackhole them until they figure it out," but it's not that easy. In many cases, the small regional ISP is the customer of a larger ISP, who is t…

> just don't let the one guy that's going to pee in the pool swim." How do you know which of the 200 people in the pool actually peed?

Sounds like a logic puzzle. I'm thinking a binary search would be the most efficient way.

Re: IP Spoofing

#30
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

I agree 100%. I've also wondered why ISPs don't do more to shut down customers that are participating in a DDOS (at least for DDOS attacks where the source IP isn't spoofed)? I would be very happy if my ISP were to let me know that something on my network is involved in an attack.

My ISP does that (XS4ALL, the Netherlands). Of course they can't know everything but if they receive abuse reports, notice your IP got blacklisted for spam or some honeypot network got a whiff of your IP address running malware variant XYZ, they put your IP address in quarantine (only 80 and 443 outgoing I think, or maybe only to the ISP's own website or something) and ask what's going on.

I can tell you they're a real pain to convince to unblock you when you are 17 and have been a bad netizen. Which is a good thing.

Post reply on HN