Possible BGP hijack
bgpstream.com
bgpstream.com
Is now being announced by AS35004 which HE shows is Ukrainian hosting provider https://netgroup.ua/
But the "Country of origin" of the AS is listed as Russian, which is perhaps where the confusion comes from. https://bgp.he.net/AS35004
About 95% of new AS35004's traffic goes through this peer: (which is Ukrainian) https://bgp.he.net/AS13249
And this peer: (which is Ukrainian) https://bgp.he.net/AS3326
Both of which Peer with Cogent.
What is interesting is that Cogent today decided to cut service to Russia. https://www.reuters.com/technology/us-firm-cogent-cutting-in...
If I was an ISP had networks from UA and RU and my Cogent peering was removed from Russia, I might move some of my traffic through my partner in Ukraine, who does have a peering arrangement with Cogent. I haven't confirmed that is what happened, but you would see this kind of shift I think if they did that.
I'm a security guy and not a CCIE so perhaps a Cisco engineer here can weigh in.
All things considered, though, I'd find an explanation of "yeah, didn't have time to update the route objects yet" to be completely acceptable.
Same situation with 95.47.59/24, by the way.
(I let my Cisco certs lapse a decade or so ago, although I've certainly originated a prefix or two over the years.)
It goes into detail. If you're just starting out, get a Network+, Security+ or any other systems administration, security or networking certification that covers the basics of networking and internetworking.
It might be a false positive: https://twitter.com/mdhardeman/status/1499877247167209480
In this thread, I will deconstruct... (1/49)
(I know youre not patrick, I made that joke almost a decade ago!)
I just haven't seen you 'round these parts recently....
May you please provide a link to your analysis of WTF might happen in recent-future times?
I was predicting a major infra/cyber war...
It seems that actions of the world have curbed that enthusiasm...
However; the spectre lingers from an info/dev/ETC/sec position ; here me out:
---
Aside from what we are seeing in the global political frame ; which means nothing to political aspirations on the personal level :
We are seeing a MASSIVE shift on the authoritarian control to global HUMAN mobility in all : Mindshare, Finance, Tech, Social-Acceptability, etc.
The RESET. is in changing the mindshare around such topics.
Lets take into your realm: Cyber-Sec...
---
Extrapolate 10 years. If you have not done so already,
What will cyber-sec look like in 10 years?
What will ID look like?
What will currency access look like?
What will financial channels for individuals look like?
What will access to "goods and services" by those who wish to not deal with "the system" look like?
What will social-mobility look like?
If you are not evaluating and thinking about this, I do not trust you
Untangling ISPs that have operated in both countries or with subsidiaries is going to get messy while infrastructure is also getting destroyed.
Alternatively, could simply be someone fat-fingering things, given the insane numbers of blocks that RosKomNadzon has been putting in today (Facebook, Twitter, etc)
Not exactly a great firewall with packet inspection, but still something to prevent any possibility to access any resources except whitelisted ones, or to run a VPN to the outside.
Update: the article in question, Google-translated: https://whatisyournameinsider-com.translate.goog/politika/24...
There's actually multiple attacks using BGP. You can either hijack the DNS or E-mail server's IP and spoof records, or you can hijack the IP of the target host and spoof an HTTP response. Or you could try all 3 to maximize your chances.
In theory i think https://en.m.wikipedia.org/wiki/Resource_Public_Key_Infrastr... is the thing that's meant to stop this attack if everyone adopted it.
Although trying to turn it on did take Slack and HBO down in the past, so someone out there cares.
I suppose I could be less snarky, but my snark here is substantive, and I'm comfortable with what it says about my seriousness. You're going to have to do better than trying to work the refs here.
It however doesn't typically help in a BGP hijack. The DNS answer is authentic, but the server at the answer given isn't.
- You own the domain trust.org pointing to IP address 2.3.4.5.
- Someone performs a BGP hijack on 2.3.4.5 and now hosts their own server on 2.3.4.5.
- They then ask Letsencrypt for a certificate to prove they are trust.org. Letsencrypt provides them a token to host on their website to prove they control it.
- Letsencrypt does a DNS lookup, sees trust.org resolves to 2.3.4.5, and performs a http request to that website to check for a token which the hijacker has duly placed on their server at 2.3.4.5.
- Letsencrypt issues a certificate for trust.org, which is now valid and controlled by the hijacker.
None of this requires access to CAs installed on anyones machine, because Letsencrypt is widely trusted and they are the ones issuing the cert.
One common way is they tell you a magic, unique string and you serve it under someguy.example/.well-known/whatever and they connect to you and verify it's there and matches. But if BGP is being hijacked, when they connect to you, they could really be connecting to some scammer. How would they know? So now some scammer has proved they're you and they'll be given a valid cert for someguy.example.
The other common verification methods have similar holes.
FWIW let's encrypt does multi perspective validation, but it is not a requirement currently.
The best thing to do as a site owner is to regularly check CT logs or use a service that does that for you.
The site owner may know about the compromised cert, but the users/clients will be blissfully ignorant and unable to do anything about it.
As of now, the world's most popular browser does not support OCSP. So revoking a cert kinda has no impact on chrome.
As we go forward, crlite is going to be required by Apple around October of this year. It's probably our current best option for browsers to use.
But yeah, you're not wrong. At the very least it would give you an idea that you were targeted and give you an idea that you need to plan for DR.
... and yet the global BGP table is absolutely full of /24s.