The compromise of the account led to the failure of BGP routing for Orange Espagne.

The compromise of the administrator account resulted in an almost four-hour outage for Orange Espagne, the second largest telecommunications operator in Spain, serving 11 million subscribers. A predictable password 'ripeadmin' was used to access the RIPE NCC registrar interface, and two-factor authentication was not enabled.

The password for RIPE was intercepted during a system compromise of one of the employees by malware and had been on sale in black market databases of compromised passwords since September. Notably, in addition to the Orange Espagne account, these databases included thousands of other accounts for connecting to access.ripe.net, which could potentially be used for similar attacks.

The incident went unnoticed until January 2, when a vandal accessed the RIPE NCC web interface and made changes to the BGP and RPKI (Resource Public Key Infrastructure) settings, causing routing disruptions for nearly four hours for approximately half of the telecommunications operator's traffic. The attackers' actions led to the RPKI technology, designed to protect BGP announcements from forgery, being used to block legitimate announcements.

The attacker created several new RPKI ROA (Route Origin Authorization) records, including records that linked large blocks of addresses belonging to Orange Espagne to an unauthorized autonomous system, which resulted in legitimate BGP announcements from this operator's autonomous system being blocked on the routers of many major operators. Ultimately, the number of BGP routes associated with Orange Espagne dropped from 9,200 to 7,400, and the traffic fell almost by half.

The compromise of the account led to the failure of BGP routing for Orange Espagne.

RPKI (Resource Public Key Infrastructure) is used for authorizing BGP announcements and allows determining whether a BGP announcement comes from the network owner or not. When using RPKI for autonomous systems and (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community. A chain of trust is built from IANA to regional registrars (RIRs), then to providers (LIR), and finally to end consumers, which allows third parties to verify that a resource operation was performed by its owner. Without authorization, any operator can announce a subnet with false routing length information and initiate transit of part of the traffic from other systems that do not filter announcements.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster