Re: [anti-abuse-wg] 213.0.0.0/8 and AS12445 (selenebs.it aka "A2A Smart City S.P.A"/Italy)

2019-04-06 Thread Siyuan Miao
Hi Ronald, It seems like a route leak to RIS or something similar like Isolario, rt-bgp.he.net. Neither of its upstream will accept 213.0.0.0/8 so it won't affect the Internet. Regards, Siyuan Miao On Sun, Apr 7, 2019 at 2:16 PM Ronald F. Guilmette wrote: > > I guess that I ha

Re: [anti-abuse-wg] Mysteries of the Internet: AS65000

2019-04-15 Thread Siyuan Miao
Hi Ronald, It's a quite simple issue and it's absolutely irrelevant to any historical or political reasons. Someone from AS56630 forgot to enable remove-private-as for eBGP peers. Regards, Siyuan Miao On Mon, Apr 15, 2019 at 4:06 PM Ronald F. Guilmette wrote: > > In messag

Re: [anti-abuse-wg] Response to ipabuseresea...@gmail.com

2020-05-10 Thread Siyuan Miao
Elad, you **really** should stop spamming any mailing list and attacking people on Twitter. On Sun, May 10, 2020 at 9:53 PM bigpigg--- via anti-abuse-wg wrote: > Hello IP Abuse Research, > > Response to your questions, misunderstanding and false information at: > https://ww

Re: [anti-abuse-wg] DDoS-Guard, a dodgy Russian firm that also hosts the official site for the terrorist group Hamas

2021-01-12 Thread Siyuan Miao
hamas.ps seems to be hosted on Sucuri ... a doggy US based firm? On Wed, Jan 13, 2021 at 10:12 AM PP wrote: > "*DDoS-Guard*, a dodgy Russian firm that also hosts the official site for > the terrorist group *Hamas"* > > > https://krebsonsecurity.com/2021/01/hamas-may-be-threat-to-8chan-qanon-onl

[anti-abuse-wg] Yet another BGP hijacking towards AS16509

2022-08-22 Thread Siyuan Miao
Hi folks, Recently I read a post regarding the recent incident of Celer Network and noticed a very interesting and successful BGP hijacking towards AS16509. The attacker AS209243 added AS16509 to their AS-SET and a more specific route object for the /24 where the victim's website is in ALTDB: (Be

Re: [anti-abuse-wg] Yet another BGP hijacking towards AS16509

2022-08-22 Thread Siyuan Miao
AS-SET209243* Looks like the first thing that AS209243 had done after they got AS1299 transit is ... hijacking an Amazon prefix ..? On Tue, Aug 23, 2022 at 1:51 AM Siyuan Miao wrote: > Hi folks, > > Recently I read a post regarding the recent incident of Celer Network and > noticed a ver

Re: [anti-abuse-wg] Yet another BGP hijacking towards AS16509

2022-08-22 Thread Siyuan Miao
Amazon was only announcing 44.224.0.0/11 at first. https://bgp.tools/prefix/44.235.216.0/24 On Tue, Aug 23, 2022 at 4:03 AM Ronald F. Guilmette wrote: > In message < > cao3camot9gc_evd-cczg06a-o_majmltxlhbxfnaudomyqo...@mail.gmail.com>, > Siyuan Miao wrote: > > >Hjack