The Route Leak Nobody Filtered — JavaScript Bug Hunt
Modelled on the Verizon/Cloudflare BGP leak (24 June 2019): a small ISP's route optimiser re-announced huge swathes of the internet as its own, and Verizon…
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Networking, Validation
- Modelled on: Verizon / Cloudflare · 2019
- Visible tests: a policy-compliant route is accepted; an over-specific prefix is rejected; an unknown origin is rejected
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Verizon/Cloudflare BGP leak (24 June 2019): a small ISP's route optimiser re-announced huge swathes of the internet as its own, and Verizon accepted the announcements without any prefix or AS-path filter. Traffic for Cloudflare, Amazon and Linode was black-holed for around two hours.
bgp.js decides whether to accept an announced route and applies no policy at all.
Fix acceptRoute so announcements outside the peer's policy are rejected.
Bug report
BUG-AS396531 · Priority: Critical · Reported by: network engineering
acceptRoute(route, policy) must accept a route only when ALL hold:
- route.prefixLen is at most policy.maxPrefixLen (more specific is a red flag)
- route.asPath.length is at most policy.maxAsPath
- route.asPath[0] is in policy.allowedOrigins
Observed: every announcement from the peer is accepted, including a /24 with a 20-hop path originated by an AS we have never heard of.
Logs
[bgp] accepted prefix=104.16.0.0/24 asPath=20 hops origin=AS33154
[bgp] 20% of global traffic now pointed at a 20Gbps peerThe code as shipped
src/net/bgp.js (editable)
// Decides whether to install an announced route.
exports.acceptRoute = function (route, policy) {
return true;
};
Read-only context: src/net/POLICY.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.