6 ms·
If the attacker knew about the Juniper bug and thought about a way to convince the network operators to introduce the rule of death themselves, then this is a n
by packetbeats 14y ago
If the attacker knew about the Juniper bug and thought about a way to convince the network operators to introduce the rule of death themselves, then this is a nice hack indeed. It won't be easy for CloudFare to generically protect against these types of attacks. They could either have mechanisms to revert configurations faster or a way to test new configurations on a single router.
- opendomain 14y agoThis is exactly my analysis. Why would the packet the attacker using be so large? The only logical reason is that they knew the Juniper bug. I am wondering if Juniper also knew this bug but did not disclose it.
- rurounijones 14y agoThe idea that the attacker knew about the bug is, I think, a remote but intriguing idea. Wonder if Cloudflare need to do some tests along the lines of: A) List up all the types of rules we usually use to mitigate these situations. B) Run those rules on a test router with wildly unusual input values, as was the case in this situation. C) Send test traffic using that wildly unexpected input to see what happens. Basically a bit of manual fuzzing Time-consuming and maybe not worthwhile, but it could save against another full system death.
- senthilnayagam 14y agoeven according to their admission, if they had not made any change the apps would all have run, just possibly some lag, but making a change for malicious user without knowing the consequence lead to this scenario.