SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    BGP Fails Again or More from the 'Hacking Team' Hack
Date    Monday July 13 2015, @09:08PM
Author    janrinok
Topic   
from the it's-only-illegal-if-you-do-it dept.
https://soylentnews.org/article.pl?sid=15/07/13/1352250

throckmorten writes:

From Ars: "Spyware service provider Hacking Team orchestrated the hijacking of IP addresses it didn't own to help Italian police regain control over several computers that were being monitored in an investigation"

http://arstechnica.com/security/2015/07/hacking-team-orchestrated-brazen-bgp-hack-to-hijack-ips-it-didnt-own/

Over a six day period in August 2013, Italian Web host Aruba S.p.A. fraudulently announced its ownership of 256 IP addresses into the global routing system known as border gateway protocol, the messages document. Aruba's move came under the direction of Hacking Team and the Special Operations Group of the Italian National Military Police, which was using Hacking Team's Remote Control System malware to monitor the computers of unidentified targets. The hijacking came after the IP addresses became unreachable under its rightful owner Santrex, the "bullet-proof" Web hosting provider that catered to criminals and went out of business in October 2013, according to KrebsOnSecurity.

It's not clear from the e-mails, but they appear to suggest Hacking Team and the Italian police were also relying on Santrex. The emails were included in some 400 gigabytes of proprietary data taken during last weekend's breach of Hacking Team and then made public on the Internet.

With the sudden loss of the block of IP addresses, Italy's Special Operations Group was unable to communicate with several computers that were infected with the Hacking Team malware. The e-mails show Hacking Team support workers discussing how the law enforcement agency could regain control. Eventually, Italian police worked with Aruba to get the block—which was known as 46.166.163.0/24 in Internet routing parlance—announced in the BGP system as belonging to Aruba. It's the first known case of an ISP fraudulently announcing another provider's address space, said Doug Madory, director of Internet analysis at Dyn Research, which performs research on Internet performance.

Also covered by Brian Krebs:

http://krebsonsecurity.com/2015/07/hacking-team-used-spammer-tricks-to-resurrect-spy-network/


Original Submission

Links

  1. "throckmorten" - https://soylentnews.org/~throckmorten/
  2. "Aruba S.p.A." - https://www.aruba.it/en/about-us.aspx
  3. "global routing system known as border gateway protocol" - http://en.wikipedia.org/wiki/Border_Gateway_Protocol
  4. "Special Operations Group of the Italian National Military Police" - https://en.wikipedia.org/wiki/Raggruppamento_Operativo_Speciale
  5. "went out of business in October 2013, according to KrebsOnSecurity" - http://krebsonsecurity.com/2013/10/bulletproof-hoster-santrex-calls-it-quits/
  6. "last weekend's breach of Hacking Team" - http://arstechnica.com/security/2015/07/hacking-team-gets-hacked-invoices-show-spyware-sold-to-repressive-govts/
  7. "made public on the Internet" - http://arstechnica.com/security/2015/07/massive-leak-reveals-hacking-teams-most-private-moments-in-messy-detail/
  8. "Dyn Research" - http://research.dyn.com/
  9. " Original Submission " - https://soylentnews.org/submit.pl?op=viewsub&subid=8281

© Copyright 2026 - SoylentNews, All Rights Reserved

printed from SoylentNews, BGP Fails Again or More from the 'Hacking Team' Hack on 2026-03-08 17:56:36