[102732] in North American Network Operators' Group
RE: YouTube IP Hijacking
daemon@ATHENA.MIT.EDU (Tomas L. Byrnes)
Mon Feb 25 12:50:08 2008
Date: Mon, 25 Feb 2008 09:37:26 -0800
In-Reply-To: <5.1.0.14.2.20080225092808.058810e0@efes.iucc.ac.il>
From: "Tomas L. Byrnes" <tomb@byrneit.net>
To: "Hank Nussbacher" <hank@efes.iucc.ac.il>,
"Steven M. Bellovin" <smb@cs.columbia.edu>, <nanog@merit.edu>
Errors-To: owner-nanog@merit.edu
This is a very interesting site. However, I notice that, in the "all in
the last 24 hours" it doesn't show the YouTube hijack. It does have a
lot of entries for 17557, most recently on 2/17.
How reliable is this system?
=20
> -----Original Message-----
> From: owner-nanog@merit.edu [mailto:owner-nanog@merit.edu] On=20
> Behalf Of Hank Nussbacher
> Sent: Sunday, February 24, 2008 11:33 PM
> To: Steven M. Bellovin; nanog@merit.edu
> Subject: Re: YouTube IP Hijacking
>=20
>=20
> At 05:31 AM 25-02-08 +0000, Steven M. Bellovin wrote:
>=20
> >Seriously -- a number of us have been warning that this could happen.
> >More precisely, we've been warning that this could happen=20
> *again*; we=20
> >all know about many older incidents, from the barely noticed to the=20
> >very noisy. (AS 7007, anyone?) Something like S-BGP will=20
> stop this cold.
> >
> >Yes, I know there are serious deployment and operational=20
> issues. The=20
> >question is this: when is the pain from routing incidents=20
> great enough=20
> >that we're forced to act? It would have been nice to have done=20
> >something before this, since now all the world's script kiddies have=20
> >seen what can be done.
>=20
> "we've been warning that this could happen *again*" - this is=20
> happening every day - just look to:
> http://cs.unm.edu/~karlinjf/IAR/prefix.php?filter=3Dmost
> http://cs.unm.edu/~karlinjf/IAR/subprefix.php?filter=3Dmost
> for samples. Thing is - these prefix hijacks are not big=20
> ticket sites like Youtube or Microsoft or Cisco or even=20
> whitehouse.gov - but rather just sites that never make it=20
> onto the NANOG radar.
>=20
> -Hank
>=20
>=20
>=20
>=20