Chinese ISP Hijacks the Internet (Again)
CWmike writes "For the second time in two weeks, bad networking information spreading from China has disrupted the Internet. On Thursday morning, bad routing data from a small Chinese ISP called IDC China Telecommunication was re-transmitted by China's state-owned China Telecommunications, and then spread around the Internet, affecting Internet service providers such as AT&T, Level3, Deutsche Telekom, Qwest Communications, and Telefonica. 'There are a large number of ISPs who accepted these routes all over the world,' said Martin A. Brown, technical lead at Internet monitoring firm Renesys. Brown said the incident started just before 10 am Eastern and lasted about 20 minutes. During that time the Chinese ISP transmitted bad routing information for between 32,000 and 37,000 networks, redirecting them to IDC instead of their rightful owners. These networks included about 8,000 US networks, including those operated by Dell, CNN, Starbucks, and Apple. More than 8,500 Chinese networks, 1,100 in Australia, and 230 owned by France Telecom were also affected."
configuration error??
It was an accident, of course.
now you can order iPad direct from china through apple.com
All that data routed to the wrong place accidentally... hmmm sounds like a perfect excuse to me - for intelligence gathering. If it passes through their routers, they have the data.
Until China learns how to act as responsible Internet citizens, I'll continue to blackhole as many of Chinese subnets as I can find both at work and home. Spam, malware, and every kind of crap comes from China, and I don't do business with any Chinese, so it's a no-brainer.
I don't respond to AC's.
"Once is an Accident, twice is a Coincidence, and three times is a Pattern."
Any sufficient level of Incompetence is indistinguishable from Malice.
Solution however is exactly the same.
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
The ISP in question only controls 30 networks, yet other routers blindly accepted thousands. Why isn't there basic verification of such re-configurations? I'm actually very shocked, the potential for abuse is huge; and TWICE as well.
... faulty by design.
Why can one "small" ISP do this? I mean from a technical point of view how can they spread routing information for endpoints their network doesn't own? While they have clearly dropped the ball, I struggle to understand how they could accomplish this even if they tried, that is if everyone else's equipment is configured correctly *cough*
How rare/common is such screwups? Or are we just bashing Chinese (not that I mind it all that much, don't let me get in the way)?
Fuck systemd. Fuck Redhat. Fuck Soylent, too. Wait, scratch the last one.
First of all don't pass by another country to go get your dns name resolution, use in home servers, second, if you are hopping through another country for x reason, you have to make sure to specify having NO name resolution until you are in local ground.
Why are they not doing something about this, this is an old problem, and still needs to be updated it seems.
Ok, China. Until you learn to play nice with the other children, you go into timeout.
Obviously the only way to protect the Border Gateway Protocol is to build a fence around it. (Spits. Scratches ass.)
"I'm not a quack, I'm a mad scientist! There's a difference." - Dr. Cockroach
So let me get this strait... IDC sent out a EIGRP instructing all these routers to direct traffic through them?
Why; God damn it WHY?!
We could of saved a lot of taxpayer dollars cutting off China instead of drafting a "cyber terrorism bill"
Notice they didn't hack Google, again. Lesson learned?
I mistyped the link. The proper URL is http://www.blockacountry.com/
IP V6 everywhere
static herarchical routing everywhere based on geographical IP addresses prefixex.
like in the old telecom way.
Limited-scope attacks like the Pakistani YouTube diversion are much more likely to be a deliberate attack; broad-spectrum attacks are obviously either mistakes (or really clever DDOS.) Advertising that you're the best route to half the world isn't exactly un-stealthy enough for intelligence gathering - and China doesn't have the bandwidth to handle that much traffic, either inside their entire country's network or especially across the Pacific; the only carriers with a chance of absorbing some fraction of AT&T's plus Level3's traffic are Verizon or possibly Google, and they're both competent enough not to do that.
This kind of thing happens occasionally with BGP, which was designed to be run in a relatively trusted environment by relatively-to-extremely-competent people, which means that it only explodes occasionally and most major carriers do a good job of filtering routing announcements that look seriously wrong, and detecting when other people advertise bogus information about their networks. The typical cause used to be bad conversions between external BGP routes and internal OSPF or RIP routes, especially back when some random customer would have left autosummarization on so they'd take their two Class C subnets, combine them into the Class A that they're both in, and announce to everybody in the world that they were the best route to reach the Tier 1 carrier who's their upstream (or who's the upstream of their local ISP, who wasn't bothering to filter their BGP announcements.)
The first time this happened in a big way was a bit of a surprise, as some little ISP announced that their T1 line was the best way to reach all of MAE-EAST (i.e. half the world), so suddenly there were gigabits of traffic headed that direction, at least until their self-DDOS killed off most of the BGP sessions and somebody fixed it. Since then, if you try to advertise being the best route to some large carrier who has a /8, you'll find they're also advertising a pair of /9s (which win), and that they'll be calling your upstream carrier within a couple of minutes to get your BGP session shut down. On the other hand, if this happens, it also means your upstream carrier wasn't filtering your BGP announcements for sanity, so they may also not be good at having somebody who can answer the phone and quickly resolve that level of problem.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
This should really be cause for alarm. Does China also use the Narus systems that the NSA is using to spy on all Americans?
Why the FUCK does USA still have internet access?
As several other people have commented, the ISPs they connect to are responsible for doing some sanity filtering on the routes they announce. It's not universal, especially for connections between ISPs (as opposed to connections from end-user customers that use BGP for multi-homing, where ISPs usually do a better job), and there's nothing close to universal agreement about address range registration systems or how to validate BGP information.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
Someone had to say it.
lovingly hand-crafted from the finest vintage 74LS stock available
The ??AA can suck it, too!
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
Our Grand Communist Party of the Great Nation of China plan to get the rest of the world to leave us alone about our glorious firewall, and desire, nay, duty to protect our citizens:
Step 1: Push out Google
Step 2: Muck up their internet
Step 3: They kick us off "their" internet
Step 4: Setup our own, national, internet
Step 5: Be praised by the lesser nations for staying off their internet, rather than chastised for walling ourselves off and keeping their realfacts out
Step 6: Spread propaganda, er... goodfacts about our Grand Communist Party of the Great Nation of China
Step 7: Unlimited, eternal power to do whatever we please
This is sort of the nature of BGP, at least when you are in the habit of trusting BGP peers. Methinks the large carriers should probably be in the habit of filtering BGP updates from chinese carriers, at least until they can pass "peering 101"
By "old-school principles", you did mean "pre-ARIN IPv4 Swamp Addresses", didn't you? :-)
Yeah, the people who designed IPv6 hoped that by having a big enough address space with no pre-existing reservations, they could make routing simpler and cleaner and delay the problem of routers running out of special route table memory and routing protocol horsepower, but that was pretty much a pipe dream:
so the IPv6 world's going to be a non-hierarchical mess just like the IPv4 world.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
'cause we created it. Thanks.
So while this was going on could the chinese save off the network traffic? They have the infrastructure Cisco routers, etc. ...
Could they decrypt SSL packets ? It may take awhile but they're not doing this real-time.
Go through any interesting attachments ? Spreadsheets, documents,
I think I'll read up more on asymmetric warfare and the Red Army officer's paper on the subject.
It was actually Pakistan, not Iran, and significant problems are more like every couple of years - and most ISPs have enough filtering to prevent most accidental screwups from getting very far, at least for very long. But yeah, it's not rare, and it only takes multi-party incompetence, not malice.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
How the hell can something like this happen? I thought the Internet was unstoppable... and a simple accident and fuck up things this much for so many people on the Internet? We need a new Internet. Seriously, we need to re-think most of our protocols.
This is unlikely to be the last this will happen. What can be done to protect against this sort of issue?
Jumpstart the tartan drive.
ISPs use BGP to talk to each other, but internally they may use iBGP or EIGRP or OSPF or (once upon a time) RIP, and they usually have a complex routing structure internally and a small number of border routers that announce a simplified set of routes to their upstream carriers or peers. Badly-automated conversions between OSPF/etc and BGP are the easiest place to make a big mistake like that, though some operators are clever enough to break their routing purely by hand.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
nuff said. Ok, I will ellaborate, but that shouldnt be neccecary. Do you really need to read more?
This may be a cyberwar between a multinational corporation and China. Google will of course win this war. The war is secret, and not fought with bullets. Oh, you want to know even more? That is hardly neccecary, but I will go on.
Also, we will need to equip an army of female acrobatic tech-warriors wearing tight-fitted latex with large open cleavages. That can probably keep the kung-fu chinese hackers at bay. Now you know all you need to know, no need to read further.
If all fails, the US must deploy the sharks with laser-beams on their heads witch they used to sever the middle-eastern Internet connection some years ago. They can keep the US coast safe from spyware. But this is all. I swear! There is no more sinister things going on.
Now, I must get back to my experiments. Nothing to see here .... move along....
Good walls work both ways. To "help" China from being tainted by the evil ways of us westerners let's just cut them off completely.
Tisha Hayes
Tier 1 & 2 ISP's should really be filtering all subnets they own. A lot of them do, but also a lot of them do not or think their Tier 2's are handling it. I've seen a company who was assigned a /24 misstype a number and suddenly they're claiming a /16 and disrupt a bunch of our customers.
Unfortunately many companies are ill equipped to detect this type of error, internally they may see everything is fine, but it's external traffic that's being detected.
It's easy if you can setup a server to check who's advertising your AS and report if things change.
While at it, I offer you to query my own Zebra server, I guarantee to only return the best available routes ;-))
http://www.gnu.org/software/zebra/
Contact me off-line if you are interested.
Seriously, I have some friends who do like you, they start by blocking China, then Korea, then end up blocking half of the world to enhance their security.
In my humble opinion, this is not a valid security approach, I actually use some requests or connection attempts from these countries to test and strengthen my security. Hackers can get to your machine from US relays/proxies or US compromised machine anyway and blocking only drops the packets as they arrive to your machine, no DOS protection or bandwidth savings.
In short, I believe blocking China gives you a false sense of security, use China to learn how to make your system secure in the first place instead but the is just my 2 cents hence my very personal opinion ;-))
Everything I write is lies, read between the lines.
It seems like Slashdot has been hit hit by China.
If I try:
http://slashdot.org/firehose
or
http://slashdot.org/~ls671/
I have been getting this for the past half hour:
Error 503 Service Unavailable
Service Unavailable
Guru Meditation:
XID: 147127282289
Varnish
Everything I write is lies, read between the lines.
I can't wait until the whole Internet goes belly up and I don't have to pay my mortgage anymore. I have a copy of Wikipedia, is all what I need to live in a world without internet.
And since a lot of spam comes from both Russia and from the US, I'll block them, too. Oh, wait a minute...
Stop the insanity China and smarten up...
We know why your doing this for, so listen up (since this is traffic is being directed to you). Do not tell us that our China ISP accidentally sent routing information, you know what you were doing, it is wrong. If you did do it by accident, than your China ISP (China Government) must be the most retarded operators or tell the truth that you want to spy for information. Either way, the rest of the world should block you and hold you responsible for your actions or use this against you for bargain (China Government - self centered freaks). I put that last part so your (China's) scanners pick this up and read it.
Racist garbage spoken like a true uninformed dickhead. Meanwhile crap like this continues to get modded up on slashdot. I'm tied of seeing almost daily china threads started on /. accompanied by racist or boarderline racist rants in the threads.
Step 8: Profit!
it's stupifying that the first post anons, when they dont talk about frosty piss, get it so right and still get modded down. /., pc less. it'll just be your and our death.
Apparently when they finally attack, it will be devastating.
SubtleAttack (1) was the ship that "ran aground" in an Australia coral reef,
traveling Km's off the normal shipping route.
Are any -other- SubtleAttacks being reported, around the world, folks...?
I'd mod you up if I could.
We need to just cut their fucking cables until they figure out how to use the goddamned Internet responsibly.
"Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
I would advise anyone using IE to change to Firefox or Opera anyway, as IE is generally insecure. Just about any other browser is safer to use than IE. http://www.articlesbase.com/health-articles/cho-yung-tea-review-amp-free-trial-2124982.html
RIPE is pushing to have all route announcements signed by 1.1.11 and the other four RIRs are following suit. Personally, I can't wait for this to happen :)
This is of course "malice aforethought", since it involves Chinese people in some way; if it had been an American ISP, then they were just unlucky, as we all know.
The Chinese aside, though, how can it be that malformed packages of any sort can just propagate? Don't the others have a natural duty to check things out a bit before they just swallow a wagonload of shite?
Hi Bill,
The really really sad thing about your comments is all of them could have easily been predicted long before there was anything like IPv6. E.g. of course businesses will want to own their own addess space. Duh!
How could IPv6 ever have been proposed without having clear responses to those objections? Did they think they could arbitrarily dictate this stuff, and that everyone would simply acquiesce?
What the fuck in his post is racist?
/. and accompanied by some idiot claiming they're racist somehow.
I'm tired of seeing almost daily china threads started on