<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors.]]></title><description><![CDATA[<p>I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. A single click on an ordinary-looking link was enough to disconnect a network from the internet.</p><p>My entry points were debugging fields in DNS and crafted TLS certificates. From there, I escalated to the RPKI Dashboard, which controls which networks are authorised to announce your IP addresses to the internet, and the RIPE Database, which stores routing policy. All vulnerabilities have been fixed.</p><p>Full write-up: <a href="https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/" rel="nofollow noopener"><span>https://</span><span>mxsasha.eu/posts/ripe-ncc-rpki</span><span>-exploit-chain/</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.hachyderm.io/media_attachments/files/116/487/151/801/231/536/original/3cb6e654e99bb923.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/64420836-8d1d-4656-bf7b-4d9132e2b64a/i-found-a-chain-of-vulnerabilities-in-systems-at-ripe-ncc-operator-of-one-of-five-global-rpki-trust-anchors.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:15:26 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/64420836-8d1d-4656-bf7b-4d9132e2b64a.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 08:54:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 18:25:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> This is phenomenal! I'm reading this on my lunch break.</p>]]></description><link>https://board.circlewithadot.net/post/https://en.osm.town/ap/users/115702352497105111/statuses/116489396470079536</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://en.osm.town/ap/users/115702352497105111/statuses/116489396470079536</guid><dc:creator><![CDATA[theorangetheme@en.osm.town]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:25:28 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 16:47:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> Interesting!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rmd1023/statuses/116489013025463363</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rmd1023/statuses/116489013025463363</guid><dc:creator><![CDATA[rmd1023@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 16:47:57 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 13:39:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> « I stumbled into the first vulnerability while debugging the reverse DNS zone for my IPv6 range in RIPEstat, RIPE NCC’s network information tool. A blue marquee started scrolling across the page, from an XSS payload I had put in my DNS server months earlier. »</p><p>actual irl lol, excellent work</p>]]></description><link>https://board.circlewithadot.net/post/https://mendeddrum.org/users/fanf/statuses/116488271132951638</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mendeddrum.org/users/fanf/statuses/116488271132951638</guid><dc:creator><![CDATA[fanf@mendeddrum.org]]></dc:creator><pubDate>Wed, 29 Apr 2026 13:39:17 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 10:07:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> thank you for your service - and a great write up for all on your discovery! <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/270c.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--v" style="height:23px;width:auto;vertical-align:middle" title="✌" alt="✌" />️<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f499.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--blue_heart" style="height:23px;width:auto;vertical-align:middle" title="💙" alt="💙" /></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/nicksilkey/statuses/116487438679596700</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/nicksilkey/statuses/116487438679596700</guid><dc:creator><![CDATA[nicksilkey@hachyderm.io]]></dc:creator><pubDate>Wed, 29 Apr 2026 10:07:35 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 09:50:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f64f.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--pray" style="height:23px;width:auto;vertical-align:middle" title="🙏" alt="🙏" /> And we live another day</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/photovince/statuses/116487373020768557</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/photovince/statuses/116487373020768557</guid><dc:creator><![CDATA[photovince@mastodon.social]]></dc:creator><pubDate>Wed, 29 Apr 2026 09:50:53 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 09:46:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> Great work Sasha (as many other things you have done! :), and thank you for responsibly disclosing it and patiently working with them to properly resolve it.</p>]]></description><link>https://board.circlewithadot.net/post/https://secluded.ch/users/jeroen/statuses/116487356115972668</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://secluded.ch/users/jeroen/statuses/116487356115972668</guid><dc:creator><![CDATA[jeroen@secluded.ch]]></dc:creator><pubDate>Wed, 29 Apr 2026 09:46:35 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 09:41:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io" rel="nofollow noopener">@<span>sash</span></a></span> ye, thats where the identity separation would come into play for me - the account that can nuke your RPKI shouldn't be the one that you do for e-learning. Though I haven't worked with RIPE NCC so I dont know how feasible that is.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116487337443940700</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116487337443940700</guid><dc:creator><![CDATA[nyanbinary@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 09:41:50 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 09:40:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/nyanbinary%40infosec.exchange">@<span>nyanbinary</span></a></span> yes, although in this case, "administrative" includes almost any RIPE NCC platform, like e-learning courses, the blog (RIPE Labs), running an Atlas measurement, submitting a talk to a RIPE meeting, and so on. The same session token covers all services.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/sash/statuses/116487331674054481</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/sash/statuses/116487331674054481</guid><dc:creator><![CDATA[sash@hachyderm.io]]></dc:creator><pubDate>Wed, 29 Apr 2026 09:40:22 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 09:37:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io" rel="nofollow noopener">@<span>sash</span></a></span> this is very cool &amp; absolutely gets me thinking about the need for separating standard sessions/identities from administrative sessions again <img class="not-responsive emoji" src="https://media.infosec.exchange/infosec.exchange/custom_emojis/images/000/587/220/original/ca392c674dc942d5.png" title=":neobot_giggle:" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116487321670924270</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116487321670924270</guid><dc:creator><![CDATA[nyanbinary@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 09:37:49 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 09:11:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/sash%40hachyderm.io">@<span>sash</span></a></span> amazing work!</p>]]></description><link>https://board.circlewithadot.net/post/https://ioc.exchange/users/wall_e/statuses/116487219418733486</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ioc.exchange/users/wall_e/statuses/116487219418733486</guid><dc:creator><![CDATA[wall_e@ioc.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 09:11:49 GMT</pubDate></item><item><title><![CDATA[Reply to I found a chain of vulnerabilities in systems at RIPE NCC, operator of one of five global RPKI trust anchors. on Wed, 29 Apr 2026 08:56:03 GMT]]></title><description><![CDATA[<p>My disclosure process with RIPE NCC took 14 months, 26 messages, and included two incorrect fixes for the same vulnerability. I wrote about the process, with thoughts on what better would look like for RIPE NCC and others: <a href="https://mxsasha.eu/posts/ripe-ncc-disclosure-retrospective/" rel="nofollow noopener"><span>https://</span><span>mxsasha.eu/posts/ripe-ncc-disc</span><span>losure-retrospective/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/sash/statuses/116487157409423571</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/sash/statuses/116487157409423571</guid><dc:creator><![CDATA[sash@hachyderm.io]]></dc:creator><pubDate>Wed, 29 Apr 2026 08:56:03 GMT</pubDate></item></channel></rss>