Another route leak. Monitoring my HostHatch transit from 3 locations:
- Amsterdam: 14:23 UTC, 847 prefixes hijacked, 6min duration
- Singapore: 14:25 UTC, partial visibility, 4min
- Sao Paulo: no impact, upstream path clean
Another route leak. Monitoring my HostHatch transit from 3 locations:
I have been a Hetzner customer for years, running stuff out of Falkenstein and Nuremberg.
I was watching the route leak unfold and checked my side. My prefixes stayed clean, traffic failed over to a secondary path inside of a minute and a half, and the ROAs I have set through their console still validated. Their NOC had already bumped alert level before I even opened a ticket.
I will update here if they publish a post-mortem, but so far this is the third time I have seen their network shrug off a leak that hit others hard. The auction servers I run for clients just kept going.
Not staff, just somebody who has too many boxes there and watches BGP too closely.
1. Good catch @uma
2. Source identification progress:
A) BGPStream showing AS4XXXXX as origin
B) But upstream is AS2YYYYY, which propagated it
C) Classic leak, not hijack
3. Impact so far:
I) Vultr customers reporting issues in APAC
Ii) Leaseweb unaffected per their status
4. My guess: config push gone wrong, not malicious
5. Waiting for more data
Hey folks
Keeping this open for technical analysis, but please stick to confirmed data. No naming specific engineers or posting private peering emails.
If you've got packet captures or MTRs, [code] tags help readability.