Vincent Canfield, the administrator of the email service and hosting reseller cock.li, discovered that his entire IP network was automatically added to the DNSBL UCEPROTECT due to port scanning from neighboring virtual machines. Vincent's subnet was listed at Level 3, where blocking occurs based on autonomous system numbers and covers entire subnets that have triggered spam detection multiple times for different addresses. As a result, provider M247 disabled announcements for one of his networks in BGP, effectively halting service.
The problem is that the substitutes servers UCEPROTECT, which impersonate open relays and log attempts to send mail through them, automatically add addresses to the block list based on any network activity, without verifying the establishment of a network connection. A similar method of blacklisting is also applied by the Spamhaus project.
It is sufficient to send a single TCP SYN packet to get on the block list, which can be exploited by malicious actors. Specifically, since bidirectional confirmation of the TCP connection is not required, a spoofed packet can be sent with a fake an IP address and initiate the blacklisting of any host. By simulating activity from multiple addresses, one can escalate the block level to Level 2 and Level 3, which enforce blocking based on subnets and autonomous system numbers.
The Level 3 list was originally created to combat providers encouraging malicious activity from clients and not responding to complaints (for example, hosting specifically set up for illegal content or servicing spammers). A few days ago, UCEPROTECT changed the rules for getting on Level 2 and Level 3 lists, leading to more aggressive filtering and an increase in the size of the lists. For instance, the number of entries in the Level 3 list rose from 28 to 843 autonomous systems.
To counter UCEPROTECT, there was an idea to use IP address spoofing from the range of UCEPROTECT sponsors during scanning. As a result, UCEPROTECT added the addresses of its sponsors and many others who were innocent into its databases, creating email delivery issues. This included the CDN network of Sucuri.
Source: opennet.ru
