I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?
I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?
(Also, sorry to be That Guy, but this one always gets to me: in the sense you've used it, it's "faze", not "phase".)
It's the same problem as FAANG collecting mountains of "anonymous" metrics. Pretty soon, you can determine who the "anonymous" user is.
We had to run the whole project on a completely separate network from the rest of the business due to the classification of the software, which was driven entirely by a handful of frequencies used in testing; details of which were also broadly available from OSINT sources.
It sounds a bit weird they would have needed 170+M ips to get a good attack sample from the internet if the ip are contiguous, a few thousands would have sufficed. It sounds very weird to expect "China" to suddenly route Xi's dirty videos and why not Iran, Japan, everyone suddenly routing craps there, it's not very targetted and would cost quite a bit to read all the potential tcp packets that got lost by bad WAN vs LAN priority decisions in routers.
Also, it's one shot, so why now ? They would have just lost a huge weapon, if true, in a very public manner, for no particular visible threat, not precise target and at great cost possibly.
I'm okay to believe this was possibly just an inventory/activation exercise because someone noticed they owned stuff they can't use until they register them.
> What is clear, however, is the Global Resource Systems announcements directed a fire hose of Internet traffic toward the Defense Department addresses. Madory said his monitoring showed the broad movements of Internet traffic began immediately after the IP addresses were announced Jan. 20.
> Madory said such large amounts of data could provide several benefits for those in a position to collect and analyze it for threat intelligence and other purposes.
It's interesting how this is framed as something "defensive in nature", when it's yet another massive funnel for data being slurped up by a US government agency.
If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies, I doubt anybody would believe a benign "Just checking our security!" explanation.
It is their IP space. It is entirely on your incompetent network staff if you are stealing IPs that are 1) not yours, 2) in use, 3) not in your country for internal use and on top of that, not rejecting external routes to it.
It is not "rerouting a ton of traffic", the traffic was destined toward them in the first place.
The DoD sitting on all that unused address space actively contributed to that problem and now it's exploiting band-aid fixes around it to once again play data kranken of the world under the guise of "We are just fighting APT!".
Somehow the discussion seem to point to China and Russia, but I know a ton of EU companies that use these ranges.
I wouldn't be surprised.
If you drive around with a WiFi stumbler running, you'll run into networks with names like "UTAH DATA CENTER" and "SIPRnet", etc for the same reason.
Made me wanna climb out of my FBI Surveillance Van and have a word with them.
In that case there's never any chance it'll be needed by people using the public internet there, and never any chance it'll be used suddenly by a deployed internal service somewhere else from an outside vendor.
The default should reserve a single ip range and simply fail (with a nice message) if more are needed.
Classic merger "solution".
Company A uses 10/8 Company B uses 10/8, company A buys company B and orders new subsidiary B to renumber into 11/8 "All you have to do is change every first octet to 11"
If your ISP doesn't provide it, get one that does. They should allocate you a /56 by default per connection, if not something larger like a /48 if you have multiple locations.
Subnet the /48 for each connection, subnet each /56 into /64 subnets. reserve one of the /56's for site-to-site if needed.
Done.
How would you "simply add two top octets"? The address fields in the IPv4 header are a fixed size of 32 bits. Every time this is discussed, someone comes up with this suggestion to "just make the addresses longer and change nothing else", but there's no way to make the addresses longer without changing something else. And that's before considering compatibility with older hosts or routers; how would an old host talk to a new host, or two new hosts talk one to another with an old router in the path? In the end, what you'd have would be two separate networks, with some hosts being in both networks, which is exactly what we have with IPv4 and IPv6.
Yeah, it works well enough until it doesn't: I love when VoIP calls have one-way audio or when I have to map ports because the traversal method used by this P2P app is not working. When run at the ISP level it's even more fun: remember when wikipedia blocked the whole Qatar?
Screw DNS. Screw the recommendation to stay away from IP's. If it's important enough to be on the network, it's important enough to have a static IP.
And by "stupid addressing scheme" do you mean it's too big, or what? You can ignore all that stuff with mac addresses and make all your addresses go like prefix:subnet::1 prefix:subnet::2 prefix:subnet::3 if you want to.
Every networking problem in the world can be solved with more NAT or more encapsulation :)
https://www.cisco.com/c/en/us/support/docs/ip/network-addres...
In both cases RFC1918 was used throughout their global network and while not fully used, had become highly fragmented over time.
They didn't actually need the addresses to be routable from the public internet (that was the whole point of the VPN). I think the requirement was really a way of making sure they were unique. I'm sure they had several partners who used 10/8 internally.
In my work we use 10.0.0.0/8 but of course some people use the same at home even though 192.168/16 is way more common. In general I find 172.16/12 the least common in the field.
It just looks nicer to me which shows the power of Apple and how easily I am influenced.
And many are surprised to find that there are 172.* that are routable.
Still gives you fun issues though.
All I had to do to make it work, IIRC, was add an ip routing rule to prioritize our internal routing for traffic on 11.0.0.0/8 instead of sending it over the default interface.
This solution worked fine, but it broke in weird ways and I remember one time I did arp -a on one of the Amazon boxes and saw some DoD registered addresses, which was a little alarming, but I just chalked it up to my not understanding the details.
If you configure your routers correctly, none of these IP addresses should resolve, anyway. If something in your network is intentionally dialing the department of defence, you probably have some kind of problem at hand. In theory this might become a huge problem, but in practice it probably won't.
[1]: https://www.juniper.net/documentation/en_US/vmx/information-...
[2]: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf...
[3]: https://security.stackexchange.com/questions/157682/why-does...
E.g. https://www.defense.gov/Resources/Military-Departments/A-Z-L...
If network operators are taking the theoretical network blocks provided in training examples and attempting to copy and paste them into real world use, that is a whole other problem with training and education. And lack of oversight by senior people who should know better at their company.
1/8 is also a whole other thing because it's a legitimately announced block controlled by, as I recall, APNIC. If it's in some peoples' 20 year old bogon folded that's their problem, not apnic's.
And then ultimately because of refusal to get over the technical hurdle of using IPv6 for internal management.
You could do the same with any AS. I haven't looked into bgp spoofing since about '99, but it seems to have matured since then. The idea of using it as ephemeral canary/honeynet space for tracking botnet C&C traffic seems like a reasonable play.
You imagine the work to figure out if my tcp heartbeats between my torrent server and my nginx proxy are CCP botnets or me misconfiguring my router ? From the same place kinda ? And you imagine the amount of people we are in China that are doing shit networking but not CCP-relevant things ?
And the amount of botnets we have in China that are to scam each other that even the CCP doesn't want ? :D
Suddenly advertise this never-used block, and you're just going to get a massive torrent of previously-internal traffic from bazillions of organizations all over the planet that used it for something internal and were slightly lazy and didn't set up their routing quite right. Probably 99.9% of it is of no use whatsoever to anyone outside that org. It's tough to imagine that anyone thought they'd get any useful information on any hostile CCP activity by doing this.
I would also expect that any department doing hostile things on the net would be at least smart enough to not let any of their internal traffic leak out like that, no matter who they actually worked for.