Scanarea porturilor a dus la blocarea subrețelei de către furnizor din cauza includerii pe lista UCEPROTECT

Vincent Canfield, administrator of the email service and reseller hosting cock.li, discovered that his entire IP network was automatically listed in the DNSBL UCEPROTECT for port scanning from neighboring virtual machines. Vincent's subnet was placed on Level 3, where blocking is conducted based on autonomous system numbers and covers entire subnets from which spam detection detectors were triggered multiple times for different addresses. As a result, the provider M247 disabled the announcement of one of his networks in BGP, effectively suspending service.

The problem is that the proxies servere UCEPROTECT, which pose as open relays and track attempts to send mail through them, automatically add addresses to the blocklist based on any network activity, without verifying the establishment of the network connection. A similar method of blacklisting is also applied by Spamhaus.

To get on the blocklist, it is enough to send a single TCP SYN packet, which can be exploited by attackers. In particular, since two-way TCP connection acknowledgment is not required, one can spoof a packet with a fake adrese IP and initiate the blacklisting of any host. By simulating activity from multiple addresses, it is possible to escalate the block to Level 2 and Level 3, which block based on subnets and autonomous system numbers.

The Level 3 list was originally created to combat providers that encourage malicious activity from clients and do not respond to complaints (for example, hosting providers specifically created to host illegal content or service spammers). A few days ago, UCEPROTECT changed the rules for being listed on Level 2 and Level 3, leading to more aggressive filtering and an increase in the list size. For example, the number of entries in the Level 3 list rose from 28 to 843 autonomous systems.

To counter UCEPROTECT, the idea of using spoofed addresses with IPs from the UCEPROTECT sponsors' range during scans has been suggested. As a result, UCEPROTECT added the addresses of its sponsors and many others innocents to its databases, creating email delivery issues. This included the CDN network of the Sucuri company being blocked.

Sursa: opennet.ro

Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS 🔥 Cumpără un hosting fiabil pentru site-uri cu protecție DDoS, servere VPS VDS | ProHoster