Re: [anti-abuse-wg] BREAKING: AFRINIC IPv4 address skulduggery FINAL REPORT - Just released

2021-01-21 Thread Ostap Efremov
Unfortunately, I am currently in an attempt to clean up all the prefixes 
announced inside of the recently revoked logicweb entry.
However, in the report and it's PDF, it does not say that it was 
revoked, which happened 4 days ago.


On 1/21/21 6:03 PM, Ronald F. Guilmette wrote:

Holy Hell!  I didn't know until this moment that the U.S. FBI was
looking into this colossal mess, starting apparently from even before
March of 2019.

Nontheless, I still claim credit for having planted the flag first.
I was publicly bitching about all of the apparent AFRINIC funny
business starting from November 17, 2016.

https://afrinic.net/20210121-afrinic-whois-database-accuracy-report


Regards,
rfg





[anti-abuse-wg] 196.52.0.0/14 revoked, cleanup efforts needed

2021-01-19 Thread Ostap Efremov
Hi,

196.52.0.0/14 was recently revoked.
Before it was revoked, the whois for this /14 was:

> inetnum:196.52.0.0 - 196.55.255.255
> netname:LogicWeb-Inc
> descr:  LogicWeb Inc.
> descr:  3003 Woodbridge Ave
> descr:  Edison, NJ 08837
> country:ZA
> remarks:REMARK
> remarks:The custodianship of this IP prefix is presently
> remarks:in dispute. A police investigation is on-going
> remarks:and AFRINIC reserves the right to
> remarks:reclaim this IP prefix at anytime.
> remarks:REMARK===
>
However, now, this /14 has been revoked by AFRINIC. Do a whois on it and
you will see, it's unallocated.
I believe this /14 was under control from our big friend from Israel, but I
don't remember.
This does not matter however.
But, sadly there are about 367 ip ranges being announced from this /14
https://pastebin.com/raw/MHaW3nPe
>From about 71 unique ASN's
This is a BOGON, unallocated space.
I would appreciate if any network that is on that list and on this mailing
list, would stop announcing parts of this hijacked /14.
I reached out to  RADB to remove all the radb entries concerning this /14,
however after 72 hours they still haven't.

> This is not an ignored ticket, we have escalated internally with our RADb
> admins and they are looking into it. I will let them know that you are
> looking for a update and we will provide it as soon as possible.

How is it possible that they can't just delete all entries? It is
UNALLOCATED SPACE, it shouldn't be routed, it shouldn't have radb.
https://www.radb.net/query?advanced_query=1=-M+196.52.0.0%2F14&-T+option=_option=&-i+option==RADB
I have also tried to post about this massive source of BOGONS on the nanog
mailing list, however, they rejected my posts.
Most likely because it possibly concerns "that one guy from Israel",
however the nanog moderators refused to comment while continuing to reject
my posts.
Their self-censorship is very destructive and harmful. I hope that if this
list is moderated, I will not have any trouble posting about this issue.

Greetings,
Ostap.