Live data from Hacker News

Shutting Down the BGP Hijack Factory

dyn.com

51–60 of 63 posts

Re: Shutting Down the BGP Hijack Factory

#51
post #45

Earlier quoted context omitted.

When the announcer doesn't immediately retract it in embarrassment, continues to announce it, the RIPE/APNIC/ARIN WHOIS data for the block continues to show ownership info other than the announcer, and the announcer doesn't produce a legitimate business relationship and LOA for why they should be announcing that "new" /18. It's usually pretty obvious.

How many hours / days / weeks do you need to give the announcer to produce all that evidence, before considering the action as malicious and undoing the announcement? Proving a business relationship sounds like a multi-day endeavor, whereas you typically want to undo the damage ASAP.

a few days, maximum. If you're $SMALLISP and you have a /22 of space, and your upstream is $MEDIUMISP, you give a LOA (letter of authorization) to $MEDIUMISP allowing them to announce your prefix to their peers and upstreams. If $MEDIUMISP can't produce that LOA on demand and the ARIN/RIPE/WHOIS/APNIC/AFRINIC whois data, email/admin/technical contacts for the /22 owned by $SMALLISP don't respond with "yup that's our block and we are allowing $MEDIUMISP to announce it", something highly fishy is going on.

Re: Shutting Down the BGP Hijack Factory

#52
No comments about the cookie warning/opt-out modal on the page? Perhaps it's only visible in the EU?

The thing explicitly takes ~2-3mins to send a HTTP POST to each of their advertising partners saying you've opted out (and warns "Some vendors cannot receive opt-out requests via https protocols so the processing of your opt-out request is incomplete")... lovely.

Re: Shutting Down the BGP Hijack Factory

#53
post #52

No comments about the cookie warning/opt-out modal on the page? Perhaps it's only visible in the EU? The thing explicitly takes ~2-3mins to send a HTTP POST to each of their advertising partners saying you've opted out (and warns "Some vendors cannot receive opt-out requests via https protocols so the processing of your opt-out request is incomplete")... lovely.

Just came here to post exactly that! What a complete mess... and if you do follow the https link, lo and behold, they re-set the settings slider to the lowest level (advertising is OK), despite having set it differently previously. Took a fair while on the https link, but at least it says it worked...

Re: Shutting Down the BGP Hijack Factory

#54
post #48
post #24

And yet still being peered - https://bgp.he.net/AS197426#_peers

The HE site takes a while to refresh.

Good point, thank you. According to the article, Hurricane depeered them on July 9th; the looking glass says it was updated 5pm July 10th, so unless the 'updated' is incorrect, Hurricane started peering this bad actor again!

Re: Shutting Down the BGP Hijack Factory

#55
post #54
post #48

Earlier quoted context omitted.

The HE site takes a while to refresh.

Good point, thank you. According to the article, Hurricane depeered them on July 9th; the looking glass says it was updated 5pm July 10th, so unless the 'updated' is incorrect, Hurricane started peering this bad actor again!

If you look up the BGP routes for a Bitcanal IP address (185.215.113.235) on HE's looking glass (https://lg.he.net/) it does not appear any routes are present. I believe HE's BGP page may still be out of date, or the peers are present but not active.

Re: Shutting Down the BGP Hijack Factory

#56
post #45

Earlier quoted context omitted.

How many hours / days / weeks do you need to give the announcer to produce all that evidence, before considering the action as malicious and undoing the announcement? Proving a business relationship sounds like a multi-day endeavor, whereas you typically want to undo the damage ASAP.

a few days, maximum. If you're $SMALLISP and you have a /22 of space, and your upstream is $MEDIUMISP, you give a LOA (letter of authorization) to $MEDIUMISP allowing them to announce your prefix to their peers and upstreams. If $MEDIUMISP can't produce that LOA on demand and the ARIN/RIPE/WHOIS/APNIC/AFRINIC whois data, email/admin/technical contacts for the /22 owned by $SMALLISP don't respond with "yup that's our…

If you think a requirement to forge a paper document is going to stop a spammer who hijacks IP space...

One more count of fraud don’t mean a thing to these criminal operations.

Re: Shutting Down the BGP Hijack Factory

#57
post #54

Earlier quoted context omitted.

Good point, thank you. According to the article, Hurricane depeered them on July 9th; the looking glass says it was updated 5pm July 10th, so unless the 'updated' is incorrect, Hurricane started peering this bad actor again!

If you look up the BGP routes for a Bitcanal IP address (185.215.113.235) on HE's looking glass ( https://lg.he.net/ ) it does not appear any routes are present. I believe HE's BGP page may still be out of date, or the peers are present but not active.

Last time I checked it took multiple days for it to update when routes disappear (I would assume they cache them for a while, in case it's just a temporary change).

Re: Shutting Down the BGP Hijack Factory

#58
post #37

Earlier quoted context omitted.

Why? It sounds incredibly pretentious. I think most people would appreciate Plain English [0]. [0] https://en.wikipedia.org/wiki/Plain_English

Because it's a lovely application of rhyming slang. https://en.wikipedia.org/wiki/Rhyming_slang

How exactly is it rhyming with anything?

Re: Shutting Down the BGP Hijack Factory

#59
post #4

We have RIPE and other IANA organizations that have routing objects in their databases with information about through which ASN certain classes are announced, there are also LOAs. GTT and Cogent are huge Tier-1 providers, why they do not check which classes their clients are announcing? Am I missing something here?

One note: not all IP addresses are handled by RIPE/ARIN/etc. There are legacy allocations which are not subject to any agreements and are the property of the owners.
Post reply on HN