Shutting Down the BGP Hijack Factory
1–10 of 63 posts
Re: Shutting Down the BGP Hijack Factory
#2Did they host it in their AS and now their AS is unreachable?
Re: Shutting Down the BGP Hijack Factory
#3http://www.bitcanal.com is down. Did they host it in their AS and now their AS is unreachable?
The ASN was mentioned in the article as being listed by Spamhaus ASN Droplist but wasn't mentioned earlier as one of the targeted ASNs.
Edit: reviewed the ASN more and it is the Ebony Horizon mentioned in the article, and it is only peered to BitCanal's primary AS197426, which is subsequently being de-peered, so I'd say that is the main reason bitcanal.com is down :) 1: http://whois.domaintools.com/bitcanal.com
Re: Shutting Down the BGP Hijack Factory
#4Re: Shutting Down the BGP Hijack Factory
#5We have RIPE and other IANA organizations that have routing objects in their databases with information about through which ASN certain classes are announced, there are also LOAs. GTT and Cogent are huge Tier-1 providers, why they do not check which classes their clients are announcing? Am I missing something here?
Any asshole can theoretically make a fraudulent LOA, but by producing one to an upstream a hijack factory opens itself up to criminal charges of fraud and forgery.
Re: Shutting Down the BGP Hijack Factory
#6I'm not sure what to do improve the situation, but there definitely seems like a need for improvement.
Re: Shutting Down the BGP Hijack Factory
#7We have RIPE and other IANA organizations that have routing objects in their databases with information about through which ASN certain classes are announced, there are also LOAs. GTT and Cogent are huge Tier-1 providers, why they do not check which classes their clients are announcing? Am I missing something here?
At the end of the day, BGP is a very trusting protocol and it requires keeping the neighborhood clean and clear. IMO providers should be filtering prefixes their clients shouldn't be announcing (al la BCP38) but keeping up on the various IP blocks being shifted around is a paperwork nightmare I'm sure.
Re: Shutting Down the BGP Hijack Factory
#8We have RIPE and other IANA organizations that have routing objects in their databases with information about through which ASN certain classes are announced, there are also LOAs. GTT and Cogent are huge Tier-1 providers, why they do not check which classes their clients are announcing? Am I missing something here?
According to a post by Job on nanog they have been known to submitted false or fabricated IRR information to RADB and RIPE: http://seclists.org/nanog/2018/Jun/379 At the end of the day, BGP is a very trusting protocol and it requires keeping the neighborhood clean and clear. IMO providers should be filtering prefixes their clients shouldn't be announcing (al la BCP38) but keeping up on the various IP blocks being shi…
Re: Shutting Down the BGP Hijack Factory
#9BGP really needs some more organized security, but that's nothing new, and i'm sure not super easy to organize.