Skip to content

Comment on Hacking Team and a case of BGP hijacking

Comments

I do not undertsand this. We recently had to change our announcement to upstream ISPs from/23 to /22 and our ISPs verified with ARIN that the entire /22 belonged to us, before changing their filters. Also, there's RADb database.

I used to work at a spam company and we did this and similar techniques.

One similar technique was we basically created our own fake ISPs, disguised as rural wireless Internet providers. Paid yearly ARIN fees, had or own /20 blocks of IP space allocated, etc. We specifically requested ip filtering completely removed from our peering connection with major upstream/backbone ISPs. They did so without question. This allowed us to source route any IP out to the Internet. Then, we would purchase large blocks of IPs (a couple of /20s a month) from Romania and Argentina. We would create GRE tunnels over to RO and route them back to the US. It's been years since I was involved so my memory of the technical details is hazy now...

Did anyone ever notice?

Not getting listed on Spamhaus was a constant battle. One time our network engineer made a huge mistake by announcing 15-20 /20 blocks registered with RIPE out of the US ASN. Spamhaus apparently automatically scans for this type of suspicious behavior and falgged like 20,000 ips.

https://en.wikipedia.org/wiki/Autonomous_system_(Internet)

your isps were competent maybe

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.