TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Possible BGP hijack

318 pointsby caaqilabout 3 years ago

7 comments

mmaunderabout 3 years ago
Prefix 31.148.149.0&#x2F;24 is normally announced by AS212463 HE shows belongs to <a href="https:&#x2F;&#x2F;dataline.ua&#x2F;en&#x2F;" rel="nofollow">https:&#x2F;&#x2F;dataline.ua&#x2F;en&#x2F;</a> which is a Ukrainian company. <a href="https:&#x2F;&#x2F;bgp.he.net&#x2F;AS35297" rel="nofollow">https:&#x2F;&#x2F;bgp.he.net&#x2F;AS35297</a><p>Is now being announced by AS35004 which HE shows is Ukrainian hosting provider <a href="https:&#x2F;&#x2F;netgroup.ua&#x2F;" rel="nofollow">https:&#x2F;&#x2F;netgroup.ua&#x2F;</a><p>But the &quot;Country of origin&quot; of the AS is listed as Russian, which is perhaps where the confusion comes from. <a href="https:&#x2F;&#x2F;bgp.he.net&#x2F;AS35004" rel="nofollow">https:&#x2F;&#x2F;bgp.he.net&#x2F;AS35004</a><p>About 95% of new AS35004&#x27;s traffic goes through this peer: (which is Ukrainian) <a href="https:&#x2F;&#x2F;bgp.he.net&#x2F;AS13249" rel="nofollow">https:&#x2F;&#x2F;bgp.he.net&#x2F;AS13249</a><p>And this peer: (which is Ukrainian) <a href="https:&#x2F;&#x2F;bgp.he.net&#x2F;AS3326" rel="nofollow">https:&#x2F;&#x2F;bgp.he.net&#x2F;AS3326</a><p>Both of which Peer with Cogent.<p>What is interesting is that Cogent today decided to cut service to Russia. <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;technology&#x2F;us-firm-cogent-cutting-internet-service-russia-2022-03-04&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;technology&#x2F;us-firm-cogent-cutting-in...</a><p>If I was an ISP had networks from UA and RU and my Cogent peering was removed from Russia, I might move some of my traffic through my partner in Ukraine, who does have a peering arrangement with Cogent. I haven&#x27;t confirmed that is what happened, but you would see this kind of shift I think if they did that.<p>I&#x27;m a security guy and not a CCIE so perhaps a Cisco engineer here can weigh in.
评论 #30563017 未加载
评论 #30564223 未加载
评论 #30565811 未加载
评论 #30567561 未加载
cjbprimeabout 3 years ago
ELI5 &quot;in Paw Patrol terms&quot; from Stamos: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;alexstamos&#x2F;status&#x2F;1499873636500475904" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;alexstamos&#x2F;status&#x2F;1499873636500475904</a><p>It might be a false positive: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;mdhardeman&#x2F;status&#x2F;1499877247167209480" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;mdhardeman&#x2F;status&#x2F;1499877247167209480</a>
评论 #30562036 未加载
评论 #30561891 未加载
评论 #30562518 未加载
drglitchabout 3 years ago
It is quite plausible that Russia would try to take down parts of Ukraine internet given everything going on.<p>Alternatively, could simply be someone fat-fingering things, given the insane numbers of blocks that RosKomNadzon has been putting in today (Facebook, Twitter, etc)
评论 #30562787 未加载
throwaway984393about 3 years ago
Gentle reminder: You can still generate valid TLS certificates for arbitrary domains with BGP hijack. Hide yo logins, hide yo passwords, and hide yo persistent sessions too, they hijackin&#x27; errrbudy up in here
评论 #30562060 未加载
评论 #30562099 未加载
评论 #30562014 未加载
评论 #30562729 未加载
thamerabout 3 years ago
This says the prefix being announced by two ASNs is only a &#x2F;24, which is kind of narrow for a hijack? Considering the countries involved, reporting this as a hijack will inevitably lead to people assuming it is related to the current conflict.
评论 #30563392 未加载
评论 #30562639 未加载
samstaveabout 3 years ago
Is Raleigh Mann not still the canon state of truth on BGP?
jokoonabout 3 years ago
I noticed reddit and other big websites were somewhat slower at one point those couples of days... I live in Europe and I wonder...
评论 #30562723 未加载
评论 #30562149 未加载