Skanowanie portów doprowadziło do zablokowania podsieci przez dostawcę z powodu wpisania na listę UCEPROTECT

Vincent Canfield, administrator of the email service and hosting reseller cock.li, discovered that his entire IP network was automatically added to the DNSBL UCEPROTECT for port scanning from neighboring virtual machines. Vincent's subnet was listed in Level 3, where blocking is done based on Autonomous System numbers, covering entire subnets from which spam detection sensors were triggered multiple times for different addresses. As a result, the provider M247 disabled the announcement of one of his networks in BGP, effectively suspending service.

The problem is that the proxies serwery UCEPROTECT, which pretend to be open relays and log attempts to send mail through them, automatically add addresses to the blocklist based on any network activity, without verifying the establishment of the network connection. A similar method of blacklisting is also utilized by the Spamhaus project.

To get onto the blocklist, it is sufficient to send a single TCP SYN packet, which can be exploited by malicious actors. In particular, as two-way confirmation of the TCP connection is not required, spoofing can be used to send a packet with a fake adresy IP and initiate the blacklisting of any host. By simulating activity from multiple addresses, one can escalate the blocklist level to Levels 2 and 3, which block based on subnets and Autonomous System numbers.

Level 3 was originally created to combat providers encouraging malicious activity from clients and who do not respond to complaints (for example, hosting services specifically created to host illegal content or service spammers). A few days ago, UCEPROTECT changed the rules for listing in Levels 2 and 3, leading to more aggressive filtering and an increase in list sizes. For example, the number of entries on Level 3 grew from 28 to 843 Autonomous Systems.

To counter UCEPROTECT, the idea of using spoofed address scanning with IPs from UCEPROTECT's sponsors' range was proposed. As a result, UCEPROTECT added the addresses of its sponsors and many others to its databases, creating email delivery problems. This included the CDN network of the company Sucuri being added to the blocklist.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster