bk99.de entertain the web since 1997

Misconfiguration as a Service: Answering undeliverable traffic sensibly

Summary

Lutz Donnerhacke intercepts misrouted customer traffic to private addresses and examines safe responses that calm faulty devices and make misconfigurations visible. Among other things, DNS, LDAP, ICMP and solar inverter control traffic was observed. The provider network itself used 100.64.0.0/10 for its customers.

Ideas

  • Customer devices accidentally send internal traffic into provider networks.
  • Unanswered packets trigger aggressive retries in some devices.
  • A catch-all machine collects traffic to private destinations that would otherwise be undeliverable.
  • Destination NAT redirects many destination addresses to controlled local services.
  • Answers have to appear to come from the originally addressed counterpart.
  • Kernel responses can end failed attempts without running risky applications.

Insights

  • Defensive answers can be more efficient than silently dropping traffic.
  • Misrouted traffic forms a passive inventory of other people’s configuration errors.
  • Address rewriting gets complicated as soon as reserved destinations and return paths meet.

Quotes

  • Was kommt denn da so geflogen? (“So what is flying in there?”) – Lutz Donnerhacke

Habits

  • Donnerhacke compares FreeBSD and Linux implementations with real packets and counters.

Facts

  • The Linux solution used nftables DNAT to the local address 127.0.0.2.

References

Critique

  • Answers that look spoofed can further blur diagnosis and boundaries of responsibility.
  • Every answering service enlarges the attack surface of the catch-all machine.

Remarks

  • In the experiment described, the FreeBSD variant failed at the desired address rewriting.
  • The follow-up article adds an authoritative DNS catch-all for the same infrastructure.

Recommendations

  • Observe misrouted traffic without active answers first.
  • Restrict catch-all services strictly to internal customer and management networks.
  • Measure retry rates, effect and new attack surfaces per protocol.

Read the original article

Search the Web Archive