meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, June 25th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 June 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cloudflare Outage; WeTransfer Leak; Jenkins Pillage @cloudflare @dolosgroup

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, June 25th, 2019 edition of the Sandsenet Storms on a stormcast.

0:07.6

My name is Johannes Ulrich.

0:09.1

And I'm recording from Jacksonville, Florida.

0:13.1

This morning, for about two hours, a major BGP route leak did affect a number of large internet sites including Cloudflare.

0:24.9

And CloudFare was the one that was most often quoted in this particular case.

0:30.8

CloudFair published a nice blog post about what exactly happened here and apparently the

0:36.9

root cause was a small internet service provider

0:39.8

in Pennsylvania DQE communications using BGP optimizer. What these optimizers typically do is they

0:48.8

well try to find the best routes for internet traffic if there are multiple options.

0:55.1

So what it did it in Cloudflare's case was that they took a larger net block that Cloudflare

1:01.6

advertised, that's usually a slash 20, split up into two slash 21s and advertised these

1:10.7

slash 21s and what was supposed to be internal to their network.

1:14.6

But apparently their upstream Verizon AS701 picked up these more specific routes and since more

1:23.3

specific routes have precedents over the more general or larger prefix.

1:30.2

These routes were now propagated to other peers connected to Verizon and AS701 this

1:37.7

Verizon network is one of these core networks in the Internet, so a lot of different services that appeared with Verizon were now trying to route their

1:50.4

traffic instead of directly to Cloudflare to this small network in Pennsylvania, which

1:57.9

of course as a result was overloaded and that then led to a denial of service

2:04.2

against Cloudflare and other affected networks.

2:09.2

This is yet another case where we sort of see one of the basic problems with BGP.

2:15.3

BGP is the protocol that allows ISP to essentially advertise which IP addresses

2:22.0

belong to them. And well, there's little to no verification if these advertisements are

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.