Smart news for curious minds.

Nerd News Network
Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

What can we learn from a BGP hijacking that poisoned production software?

Lead image for “BGP hijack infecting networks caused by a comedy of errors that’s not funny at all”.
Image: Ars Technica
Share

What can we learn from a BGP hijacking that poisoned production software?

The short version

  • Softaculous used the IPs to issue updates and host a client and billing site.
  • With control over the hijacked space, the attacker was now using the addresses to push malware masquerading as updates to unsuspecting users.
  • Lax configuration of routing security in Softaculous’ hosting provider, Hetzner Online, was the major contributor to the hack.

What happened

A large number of other errors contributed to the success of the attack. Most notably, Softaculous failed to follow one of the most common safety steps in software development, which is to validate software updates using code signing.

Why it matters

A loose configuration by Hetzner Online allowed hijackers to intermittently misdirect traffic over two spans in a 33-hour window.

Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.

Share