Misconfiguration as a Service: Answering undeliverable traffic sensibly
Summary
Lutz Donnerhacke intercepts misrouted customer traffic to private addresses and examines safe responses that calm faulty devices and make misconfigurations visible. Among other things, DNS, LDAP, ICMP and solar inverter control traffic was observed. The provider network itself used 100.64.0.0/10 for its customers.
Ideas
- Customer devices accidentally send internal traffic into provider networks.
- Unanswered packets trigger aggressive retries in some devices.
- A catch-all machine collects traffic to private destinations that would otherwise be undeliverable.
- Destination NAT redirects many destination addresses to controlled local services.
- Answers have to appear to come from the originally addressed counterpart.
- Kernel responses can end failed attempts without running risky applications.
Insights
- Defensive answers can be more efficient than silently dropping traffic.
- Misrouted traffic forms a passive inventory of other people’s configuration errors.
- Address rewriting gets complicated as soon as reserved destinations and return paths meet.
Quotes
Was kommt denn da so geflogen?
(“So what is flying in there?”) – Lutz Donnerhacke
Habits
- Donnerhacke compares FreeBSD and Linux implementations with real packets and counters.
Facts
- The Linux solution used nftables DNAT to the local address 127.0.0.2.
References
- Lutz Donnerhacke: Fehlkonfig as a Service (German)
- RFC 1918: private IPv4 address ranges.
- RFC 6598: Shared Address Space 100.64.0.0/10.
Critique
- Answers that look spoofed can further blur diagnosis and boundaries of responsibility.
- Every answering service enlarges the attack surface of the catch-all machine.
Remarks
- In the experiment described, the FreeBSD variant failed at the desired address rewriting.
- The follow-up article adds an authoritative DNS catch-all for the same infrastructure.
Recommendations
- Observe misrouted traffic without active answers first.
- Restrict catch-all services strictly to internal customer and management networks.
- Measure retry rates, effect and new attack surfaces per protocol.
Links to the original source and the Web Archive open in a new tab.