[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

AS3266: BitCanal hijack factory, courtesy of many connectivity providers

On Tue, Jun 26, 2018 at 09:57:14PM +0200, Radu-Adrian Feurdean wrote:
> On Tue, Jun 26, 2018, at 20:23, Job Snijders wrote:
> > I'm very happy FranceIX apply filters - however Bitcanal is known to
> > submit fabricated/falsified IRR information to databases like RADB
> > and RIPE. I've reported this multiple times over the years to IRR
> > database operators.
> > 
> > In conclusion in the case of Bitcanal, most of your filtering is
> > useless (and so is mine). Participants like Bitcanal dillute the
> > value of your route servers and the IXP as a whole.
> I can confirm that this mornig (~09h30 CEST, when I read the first
> message in the thread) there were no BitCanal announces received from
> FranceIX Paris RS.

What about now? Still squeaky clean? What about now? What about
tomorrow? You only need to announce hijacked routes for the duration of
the spamming campaign (usually just a few hours). The presence of this
type of actor poses a risk to all connnected to the IX fabric.

Kind regards,