How a Router’s Missed Range Check Nearly Crashed the Internet

“A bug by router vendor A (omitting a range check from a critical field in the configuration interface) tickled a bug from router vendor B (dropping BGP sessions when processing some ASPATH attributes with length very close to 256), causing a ripple effect that caused widespread global routing instability last week. The flaw lay dormant until one of vendor A’s systems was deployed in an autonomous system whose ASN, modulo 256, was greater than 250. At that point, the Internet was one typo away from disaster. Other router vendors, who were not affected by the bug, happily propagated the trigger message to every vulnerable system on the planet in about 30 seconds. Few people appreciate how fragile and unsecured the Internet’s trust-based critical infrastructure really is — this is just the latest example.”

Vendor A, in this case, is a Latvian router vendor called MikroTik.

Checkout Renesys.com for more details, and coverage.

Share and Enjoy:
  • Print
  • PDF
  • RSS
  • Digg
  • Slashdot
  • Google Bookmarks
  • Live
  • Yahoo! Bookmarks
  • Twitter
  • Facebook
  • MySpace
  • HackerNews
This entry was posted in technology and tagged , , , , , , , , , . Bookmark the permalink. Both comments and trackbacks are currently closed.

Welcome SNX User SNX Consulting

Log in

Lost your password?

Register For This Site






Too Short Hint: Use upper and lower case characters, numbers and symbols like !"?$%^&( in your password.


Enter the text from the image.

Welcome Guest

Please Register/Login to gain access to appointment scheduling, support, and invoice payments.