Skip to main content

Insecure routing redirects YouTube to Pakistan

Popularity Report

Total Popularity Score: 0

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...

Rank

Bookmark History

Saved by 5 people (-1 private), first by anonymouse user on 2008-02-25


Public Sticky notes

packets sent to YouTube were flowing to Pakistan

Highlighted by sudhang

Pakistan government had just instituted a ban on the popular video sharing site

Highlighted by sudhang

Pakistan Telecom routed the address block that YouTube's servers are in to a "black hole" as a simple measure to filter access to the service

Highlighted by sudhang

escaped from Pakistan Telecom to its ISP PCCW in Hong Kong, which propagated the route to the rest of the world

Highlighted by sudhang

on 2008-02-25 by sudhang

How?????

Classless Inter-Domain Routing (CIDR)

Highlighted by sudhang

CIDR allows address blocks to be given out in power of two blocks

Highlighted by sudhang

The number after the slash indicates how many of the 32 address bits are "network" bits, the remaining bits are used to number hosts.

Highlighted by sudhang

a particular IP address can now fall within multiple address ranges.

Highlighted by sudhang

So even though YouTube's routing information was still there, packets would flow towards Pakistan Telecom because of the longest match first rule.

Highlighted by sudhang

on 2008-02-25 by sudhang

Since the range specified by Pakistan Telecom was narrower, routers gave precedence to the Pakistan Telecom... So, packets intended for YouTube made their way to PT instead!!