Orange EspaƱa was hacked because the password for the admin account of RIPE NCC was ripeadmin.

Orange EspaƱa, the second largest mobile operator in Spain, experienced a severe outage on Wednesday after an unknown party accessed the account used to manage the global routing table with a "ridiculously weak" password. Starting at 9:28 UTC, an individual using the nickname Snow logged into the Orange account at RIPE NCC, using the password ripeadmin. RIPE NCC is responsible for managing and distributing IP addresses and serves 75 countries across Europe, the Middle East, and Central Asia.

Snow initially added new ROAs (Route Origin Authorizations) to the global routing table, which didn’t cause any issues at first. However, later on, Snow added ROAs with "fake sources," which led to a significant reduction in the valid routes for Orange, causing a service disruption. This problem was exacerbated by the use of the RPKI (Resource Public Key Infrastructure) system, designed to prevent the unauthorized interception of routes, effectively rendering Orange's network non-functional.

The company Hudson Rock discovered credentials for sale in online marketplaces, obtained through malware installed on Orange's computers since September. Researchers also noted thousands of other credentials securing RIPE accounts available in such marketplaces.

This incident highlights the fragility of the BGP system and reveals serious security issues within Orange. The use of a weak password and the absence of multi-factor authentication, combined with malware installed on an employee’s computer that went unnoticed for four months, are serious oversights that should never have occurred in an organization of Orange’s size. Researchers hope that this incident serves as a wake-up call for other service providers and prompts them to strengthen their security measures.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers šŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster