Earlier quoted context omitted.
When the announcer doesn't immediately retract it in embarrassment, continues to announce it, the RIPE/APNIC/ARIN WHOIS data for the block continues to show ownership info other than the announcer, and the announcer doesn't produce a legitimate business relationship and LOA for why they should be announcing that "new" /18. It's usually pretty obvious.
How many hours / days / weeks do you need to give the announcer to produce all that evidence, before considering the action as malicious and undoing the announcement? Proving a business relationship sounds like a multi-day endeavor, whereas you typically want to undo the damage ASAP.
Shutting Down the BGP Hijack Factory
51–60 of 63 posts
Re: Shutting Down the BGP Hijack Factory
#52The thing explicitly takes ~2-3mins to send a HTTP POST to each of their advertising partners saying you've opted out (and warns "Some vendors cannot receive opt-out requests via https protocols so the processing of your opt-out request is incomplete")... lovely.
Re: Shutting Down the BGP Hijack Factory
#53No comments about the cookie warning/opt-out modal on the page? Perhaps it's only visible in the EU? The thing explicitly takes ~2-3mins to send a HTTP POST to each of their advertising partners saying you've opted out (and warns "Some vendors cannot receive opt-out requests via https protocols so the processing of your opt-out request is incomplete")... lovely.
Re: Shutting Down the BGP Hijack Factory
#54And yet still being peered - https://bgp.he.net/AS197426#_peers
The HE site takes a while to refresh.
Re: Shutting Down the BGP Hijack Factory
#55Earlier quoted context omitted.
The HE site takes a while to refresh.
Good point, thank you. According to the article, Hurricane depeered them on July 9th; the looking glass says it was updated 5pm July 10th, so unless the 'updated' is incorrect, Hurricane started peering this bad actor again!
Re: Shutting Down the BGP Hijack Factory
#56Earlier quoted context omitted.
How many hours / days / weeks do you need to give the announcer to produce all that evidence, before considering the action as malicious and undoing the announcement? Proving a business relationship sounds like a multi-day endeavor, whereas you typically want to undo the damage ASAP.
a few days, maximum. If you're $SMALLISP and you have a /22 of space, and your upstream is $MEDIUMISP, you give a LOA (letter of authorization) to $MEDIUMISP allowing them to announce your prefix to their peers and upstreams. If $MEDIUMISP can't produce that LOA on demand and the ARIN/RIPE/WHOIS/APNIC/AFRINIC whois data, email/admin/technical contacts for the /22 owned by $SMALLISP don't respond with "yup that's our…
One more count of fraud don’t mean a thing to these criminal operations.
Re: Shutting Down the BGP Hijack Factory
#57Earlier quoted context omitted.
Good point, thank you. According to the article, Hurricane depeered them on July 9th; the looking glass says it was updated 5pm July 10th, so unless the 'updated' is incorrect, Hurricane started peering this bad actor again!
If you look up the BGP routes for a Bitcanal IP address (185.215.113.235) on HE's looking glass ( https://lg.he.net/ ) it does not appear any routes are present. I believe HE's BGP page may still be out of date, or the peers are present but not active.
Re: Shutting Down the BGP Hijack Factory
#58Earlier quoted context omitted.
Why? It sounds incredibly pretentious. I think most people would appreciate Plain English [0]. [0] https://en.wikipedia.org/wiki/Plain_English
Because it's a lovely application of rhyming slang. https://en.wikipedia.org/wiki/Rhyming_slang
Re: Shutting Down the BGP Hijack Factory
#59We have RIPE and other IANA organizations that have routing objects in their databases with information about through which ASN certain classes are announced, there are also LOAs. GTT and Cogent are huge Tier-1 providers, why they do not check which classes their clients are announcing? Am I missing something here?