Noction - could be but there were not many specifics in around 3200 routes
they originated, there were few /12, /13, /14
mistake probably.
121.128.0.0/12 39120 65478 25478
121.128.0.0/12 61568 65478 25478
121.144.0.0/13 61568 65478 25478
141.48.0.0/13 61568 65478 25478
203.40.0.0/13 39120 65478 2
Based on my own observation as well as via bgpstream there was a massive
BGP hijack attempt last night by IHOME-AS iHome LLC, RU (AS 25478).
Lasted about 10 minutes. Noction? Finger faddle? Malicious?
Thanks,
Hank
In response to feedback from operational security communities,
CAIDA's source address validation measurement project
(https://spoofer.caida.org) is automatically generating monthly
reports of ASes originating prefixes in BGP for systems from which
we received packets with a spoofed source address.
3 matches
Mail list logo