Homeless Vikings

 

Don't try it at home

 

How easy is this to pull off? Trivial

  • You can use a shady ISP
  • You can BE a shady ISP
  • You can work at an ISP and be shady

But even given none of the above, "mistakes" happen.

  • Even top tier ISP's can forget to use proper BGP filters.
  • They have no way to filter advertisements from customers originating in the proper net block.
  • Top tiers are focused on mitigating DDOS and Worm attacks, and usually don't consider a 15 minute misconfiguration to be a "security problem".