Hijacking machine: ASAS201640 / AS200002

2014-10-31 Thread Ronald F. Guilmette
I don't routinely follow this list, so I'm not sure how much of this is common knowledge already, but... http://blogs.cisco.com/security/talos/help-my-ip-address-has-been-hijacked/ Current route announcements for AS201640: 36.0.56.0/21 probable hijack - China 41.92.206.0/23probable h

Re: Hijacking machine: ASAS201640 / AS200002

2014-10-31 Thread Jima
On 2014-10-31 17:20, Ronald F. Guilmette wrote: P.S. If anybody is able to look up _all_ of the route announcements that have been made by AS201640 over the past few months, I for one would definitely like to see those. Hello again, Ronald. I don't know for certain that it's all-inclusive,

Re: Hijacking machine: ASAS201640 / AS200002

2014-10-31 Thread Ronald F. Guilmette
In message <54542174.30...@ghostnet.de>, Armin Kneip wrote: >http://bgpupdates.potaroo.net/cgi-bin/generate_as_log?as=201640 >http://bgpupdates.potaroo.net/cgi-bin/generate_as_log?as=22 > >or > >http://www.cidr-report.org/cgi-bin/as-report?as=AS201640&view=2.0 >http://www.cidr-report.org/cg

Re: Hijacking machine: ASAS201640 / AS200002

2014-10-31 Thread Rob Mosher
While it's not a thorough list of all announcements, here are nightly snapshots courtesy of http://bgp.he.net AS201640: http://pastebin.com/nvuVbnpn AS22: http://pastebin.com/1JZnWadD -- Rob Mosher Senior Network and Software Engineer Hurricane Electric / AS6939 On 10/31/2014 11:57 PM, Ron

Re: Hijacking machine: ASAS201640 / AS200002

2014-11-01 Thread Rene Wilhelm
On 11/1/14, 2:03 AM, Jima wrote: On 2014-10-31 17:20, Ronald F. Guilmette wrote: P.S. If anybody is able to look up _all_ of the route announcements that have been made by AS201640 over the past few months, I for one would definitely like to see those. Hello again, Ronald. I don't know

Re: Hijacking machine: ASAS201640 / AS200002

2014-11-01 Thread Jared Mauch
On Fri, Oct 31, 2014 at 08:57:09PM -0700, Ronald F. Guilmette wrote: > > In message <54542174.30...@ghostnet.de>, > Armin Kneip wrote: > > >http://bgpupdates.potaroo.net/cgi-bin/generate_as_log?as=201640 > >http://bgpupdates.potaroo.net/cgi-bin/generate_as_log?as=22 > > > >or > > > >http://

Re: Hijacking machine: ASAS201640 / AS200002

2014-11-01 Thread Armin Kneip
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Ronald, > P.S. If anybody is able to look up _all_ of the route announcements that > have been made by AS201640 over the past few months, I for one would > definitely like to see those. Please e-mail them to me off list. I > already know tha

Re: Hijacking machine: ASAS201640 / AS200002

2014-11-01 Thread Bryan Socha
BGPlay found at https://stat.ripe.net/ is back and I find easier to look back at bgp tables and find events like another AS or more specific route appearing. Also if you never looked, bgpmon.net is a decent service to monitor import announcements and AS numbers to get near real time alerts of rout