Botnet Attack on BSNL Broadband network

  • Thread starter Thread starter Sushubh
  • Start date Start date
  • Replies Replies 121
  • Views Views 12,265
Thanks @airforce. BSNL's public IP ranges are public information, probably when the attackers noticed increased success rate for BSNL IP ranges, they may have targetted BSNL IP ranges more extensively.

Also, once you insert a malicious DNS resolver, they can potentially hijack your traffic elsewhere for non HTTPS traffic.

I'm still curious to know, how the attack itself worked, and what kind of workload the affected PC's or networks were being made to do.
 
The attack itself must be a typical botnet way... scan for vulnerable devices, infect them and wait for trigger instruction to start DDoS attack.

What we don't know is that was BSNL network itself a target of the attack or some other target.
 
I'm curious to know what really happened. Was malicious code inserted into the ONT? Is that why the data usage went up? If so can something running on that ONT hardware generate so much of data? Also, has anyone actually got into an affected ONT over SSH or something and checked what was happening?

I am curious did it happen to OLTs or bsnl backend too? even if ONT is hacked nobody can cross 21GB/day on 2mbps like it happened to me(30+ GB and mostly uploads) or did they find an exploit for PPP/RADIUS servers too? for some users even POST -FUP 2 TB data usage is crossed which is insane.

Also right now for fuptopup sub-domain is down , but 172.xx.xx.xx based fup is working? and selfCare portal is not registerin my today's data usage(it shows no record, i checked it multiple times)
 
Maybe it's the time bsnl takes security seriously.
There have been incidents of malicious code and stuff lurking in BSNL's infrastructure and I think this is the worst hit of them all.
If Bsnl wants to be proper bb isp then they need to overhaul their infrastructure and start peering aggressively within india and fix thier hopeless routing.
Isps like excitel exists and thier tariff are insanely low because they have cracked the code of peering.
Peering with Content players will bring down the cost. Half the BSNL domestic traffic goes out of the country to reach the destination because of thier too much reliance on transit providers and lack of peering.
 
Noob question: Does peering has significant cost for an ISP especially BSNL level?(like power infrastructure,bandwidth provisioning for peers etc..)
 
Cost of peering depends on the network you want to peer and thier peering policy.
Companies like Google,Facebook etc have open peering policy where if you have an ASN with decent traffic you can peer with them directly and don't have to pay anything for it but you have to take care of the infrastructure cost on your side.
For a big player like bsnl these cost will be negligible when they compare it with cost of paying a transit provider like airtel or tata.
Similarly if you don't peer to a network directly and want to peer with an internet exchange like extremeIX or Bharath Ix the you have to pay for the port charge (Specified amount like X amount for an 1G port).
When peering with Ix you can have traffic to all the other members of that particular IX.
 
Isn't 1 G port is too small for an IX I was expecting atleast 40G ports?

(I will end the conversation here as I don't want to derail the main conversation of the thread)
 
Well I think its because of they attitude of the upper level employees .They wouldn't simply do anything wont they till now .but I hope they will start improving their peering since jio fiber is spreading to many places
 
I wasn't trying to nit-pick you, I meant to say for IX level anything lest than 40G sounds small unl;ess IX are in business of providing 1-20 Gbps ethernet to corporate or private players?
 
Back