Home page logo
/

nanog logo nanog mailing list archives

Re: AS8300 - Swisscom hijacking.. Just what are you testing?
From: Jared Mauch <jared () puck nether net>
Date: Wed, 1 Feb 2012 17:22:11 -0500


On Feb 1, 2012, at 5:12 PM, Jeroen Massar wrote:

On 2012-02-01 22:44 , Schiller, Heather A wrote:

AS8300 started announcing one of the Rove Digital dns changer IP ranges.
[..]
I searched around and couldn't find any mention of what they might be testing.  Anyone know?  

They do internal aggregation of common prefixes to keep their internal
tables small, see for instance this rather old preso:

http://www.swinog.ch/meetings/swinog7/BGP_filtering-swinog.ppt

These prefixes should of course not be leaked outside their own network.

I would say, kick them either directly (yell offlist if you want direct
contacts) or spam the SwiNOG list and you will get a response quickly too.

One could just filter their as-path from 701/702/703 in the interim to get them to address it.

- jared

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault