The Register Home Page

back to article 33-hour BGP hijack of Softaculous traffic prompts security scramble

Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted traffic and delivered malware to a handful of installations. Softaculous makes software for the web hosting industry, while its Virtualizor control panel is used by providers and …

  1. Anonymous Coward
    Anonymous Coward

    It seems that the upstream provider, Hetzner AG, does have an RPKI ROA for their /16 range, with a maxlength of /24; but that a lot of people out there still aren't doing RPKI validation. That would have blocked this hijack.

    1. Anonymous Coward
      Anonymous Coward

      Actually, looking at this in more detail; they spoofed the source ASN as well, so RPKI wouldn't have stopped this. When can we have ASPA widely deployed, please?

      1. FirstTangoInParis Silver badge

        Good write up on this topic here https://blog.cloudflare.com/aspa-secure-internet/

  2. Clausewitz4.1 Bronze badge
    Devil

    Origin of route hijack

    Will AS62390 (NexonHost) explain itself?

  3. Anonymous Coward
    Anonymous Coward

    Certificate?

    How could they get a certificate? I suppose if they got control of the IP, they'd send out a request to let's encrypt from there and let's encrypt would connect back to the attackers machine to authorize the certificate.

    This would be a HUGE hole, as this is basically the whole point of having certificates in the first place.

    What am I missing here?

    1. DS999 Silver badge

      Re: Certificate?

      Yes having recently set up Let's Encrypt you can do it via placing something on your HTTP server (which I don't have) or in your DNS (which is what I used) That gives you two routes to fake a certificate though, taking control of their IP range lets you do it the HTTP way, taking control of their registrar's account (assuming they have them doing their DNS for them, which most do these days) lets you do it another way.

    2. Kurgan Silver badge

      Re: Certificate?

      The fact that unless you have a real person come to see you and see your credentials (documents, etc) and validate that you are who you say you are, there is no way to completely avoid fake certs being issued. And even then, you could produce fake evidence, fake documents, etc. Or the whole CA could be compromised / colluded. Certificates are not 100% secure.

  4. DoctorPaul Bronze badge

    Infosec failing?

    "Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis."

    It's so boring doing that security stuff isn't it?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon