North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: YouTube IP Hijacking

  • From: Rick Astley
  • Date: Mon Feb 25 01:57:35 2008
  • Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; bh=IF6QwPUF3jJD0sb2H+OU1MryeGfr3M93mE7zjOqypB0=; b=vTsxqLPvfpcQWRMMUPzTl8mDjEa3OpEvRdyZoT0I6ye6H4F5RgLzj37PXOTvxQ4uv+izj3fLnXVQf1jYkGsTGRwJnHoVGm5qk42IR3+CLncP7lSiF2blm4k4b2E0np2hJFIBhV0iH0xygnjPAQBP0xXT5pPSg5qCEK21O9gifxY=
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; b=k+yNBzgBl48W9VWaItshFtWF9hYiQeFpl33k/TKrow2lLbppdYJZ7H9J9RCm6tb5xS3L5t3wvs1nZXdMFAHnpVWM54/uanJ50vBanJ6r7Rr7d3yJn9o/Tdt/8scbOuiQlsKUAZ8XC+2o2k1rGjANdLdN9+Yuj5ltYIZsdK79DOE=

It does sort of shed light on a sobering fact that some of the PCCW's of the world are not using proper filtering, and with a coordinated effort, someone could inject a large number of routes into the global routing table through them effectively taking offline much of the Internet.

Anything more specific than a /24 would get blocked by many filters, so some of the "high target" sites may want to announce their mission critical IP space as /24 and avoid using prepends.

If the PCCW's of the world are not going to sanity check inbound announcements from some of their peers, they should at least be prepending them to help fight abuse of this nature (accidental or not).

Also, IANAL, but there seems to be a misconception of what AT&T's DDoS patent (application 20060031575) covers. The patent is not simply about blackholing an IP address, it claims "Such a selective black-holing scheme can be used to allow some traffic to continue in route to the IP address under attack, while other traffic is diverted."

So simply blackholing everything destined to an IP address does not seem to conflict with the patent.

As a side note, it will be interesting to see how the youtube posters respond to this.
If Pakistan thought the site was offensive before, I doubt they will be amused at the backlash that will probably occur as the result of this.

I have a feeling youtubers will be trying to 1up each other for most offensive video.