Cisco vulnerability and dangerous filtering techniques

Just a handful of traceroutes would give it enough information to start
at a major backbone and work back towards itself.

-SW

Just a handful of traceroutes would give it enough information to start
at a major backbone and work back towards itself.

I guess all folks with Ph.D. at Akamai really are paid for nothing if a
virus could calculate that with a few traceroutes.

Alex

It's actually pretty easy if you get 20K distributed zombies doing the traceroutes
and then distributing the data to each other. Given that data, it's pretty easy to
compute the graph - every router running BGP has to do similar. :slight_smile:

The Akamai problem is how to do it *without* having 20K boxes doing traceroutes. :wink:

> I guess all folks with Ph.D. at Akamai really are paid for nothing if a
> virus could calculate that with a few traceroutes.

It's actually pretty easy if you get 20K distributed zombies doing the
traceroutes and then distributing the data to each other. Given that
data, it's pretty easy to compute the graph - every router running BGP
has to do similar. :slight_smile:

Sounds like said virus implementor should go into the optimized routing
business. Personally I'm gonna call bullshit on that one until I see it
done.

The Akamai problem is how to do it *without* having 20K boxes doing
traceroutes. :wink:

How many boxes does Akamai have? :slight_smile:

> I guess all folks with Ph.D. at Akamai really are paid for nothing if a
> virus could calculate that with a few traceroutes.

Let's hope not. :slight_smile:

It's actually pretty easy if you get 20K distributed zombies doing the
traceroutes and then distributing the data to each other. Given that
data, it's pretty easy to compute the graph - every router running BGP
has to do similar. :slight_smile:

I am not sure why you would even need "a few" traceroutes. Why not just load the virus with, say, the top 10 or 100 ASes, then use one of those kewlio traceroute programs that give you AS info. Do *one* or maybe a couple traceroutes, hit the last big AS in the list, and work your way back home.

Sounds like said virus implementor should go into the optimized routing
business. Personally I'm gonna call bullshit on that one until I see it
done.

No comment. :slight_smile:

The Akamai problem is how to do it *without* having 20K boxes doing
traceroutes. :wink:

How many boxes does Akamai have? :slight_smile:

Last press release was a little over 15K boxes in over 1100 networks in 66 countries. But I would not call them zombies.

Is that more or less distributed than your typical 'bot-net?