Skip to content

My subnet got hijacked for 20 minutes—how do I prevent repeat?

Networking by lucgone 24 replies 1.5K views
2 #1

Hello, I have make a bad discovery since 2 days. My /24 subnet was hijacked for 20 minutes, someone has announce it on another ASN and my traffic was redirect. I check RIPE (https://www.ripe.net) and my ROA was... not there? I have make it in 2023, I am sure.

It is possible to do that? The RPKI is not supposed to prevent this? I am confused lol. My provider is KnownHost, they say "not our problem, contact RIPE". Mdr.

What I should do now? I don't want this repeat

Vive la résistance... électrique
4 #2

The Vorld Is Full Of Surprises.

I Have Checked The Certificate Transparency Logs And The Roa For Your Prefix Is Not Visible. The Rir Interface Sometimes Fails Silently; This Is A Known Issue Since The "Upgrade" In January.

You Should Validate In The Ripe Ncc Web Interface Directly. Do Not Trust The Api Response Alone.

apt-get install everything
#3

The actual published manifest was empty. Took me ages to spot.

$ rpki-client -t | grep 203.0.113.0/24
# nothing. absolutely nothing.

It actually works once you re-sign, but their "save" button doesn't always save. Hit it twice, check the.roa file downloads.

What RIR are you with?

works on my bench ¯\_(ツ)_/¯
#4

Chur @tomchan, yeah that's the one mate? Ripe's interface is proper broken aye, been like that since their "improvement"?

@lucgone your english is sweet as btw, "I have make" is classic? We know what you mean though mate

Did you try the api vs the web ui? Different databases sometimes, no joke?

#5

This is precisely why the EU mandated RPKI adoption in the 2019 framework; Article 13 (not the copyright one, the telecommunications one) required member states to implement route validation mechanisms. Yet here we are, dependent on broken interfaces.

I have filed complaints with my national regulator regarding RIR accountability. GDPR does not apply to RIRs directly, but the principle of data integrity should. Your routing data is personal data in a broad interpretation.

Document everything. Screenshot the broken interface. This is evidence for the next policy review cycle.

#6

Their "save" button is a menace. Hit it three times.

#7

January upgrade broke more than it fixed, typical

your margin is my opportunity
#8

Thank you all. I have login to RIPE again and... the ROA is there now? I have not touch anything since 2023. But the "last modified" say 2023, so it was always there? I am more confused.

I have download the .roa file, it is valid. So why rpki-client show nothing before? Maybe the problem is not RIPE but the publication server?

KnownHost say again "not our problem" but they are my upstream, they should filter invalid routes no? Or at least validate? I am on their Amsterdam datacenter — https://www.knownhost.com.

Vive la résistance... électrique
#9
lucgone said:
They should filter invalid routes no?

No. Your provider is a transit customer, not a peer. They receive the hijacked route from their upstreams or peers, and unless they run RPKI validation on *all* received routes and drop RPKI-invalid, the leak propagates. Most providers don't do strict RPKI filtering because it breaks things during partial deployments.

You want IRR filters plus RPKI, and you want your provider to at least do RPKI-based tagging. But "should" and "does" are different continents on this internet.

Check your ROA's max length. If you announced a /24 and the ROA says /24, fine. If it says /22, someone can hijack a more-specific.

iBGP, eBGP, don't care, just peer
2 #10
lucgone said:
The "last modified" say 2023

The object was there. The manifest wasn't serving it. Classic RIPE rsync lag, their new publication infrastructure has gaps.

Run this from two different vantage points:

$ dig +short txt 113.0.203.rpz-ip.ripe.net

If you get NXDOMAIN from one resolver and a record from another, their anycast is split-brain again. Happened in March too.

works on my bench ¯\_(ツ)_/¯

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft