[109195] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Fwd: RE: Potential Prefix Hijack

daemon@ATHENA.MIT.EDU (Scott Weeks)
Tue Nov 11 00:29:39 2008

Date: Mon, 10 Nov 2008 21:29:34 -0800
From: "Scott Weeks" <surfer@mauigateway.com>
To: <nanog@merit.edu>
Reply-To: surfer@mauigateway.com
Errors-To: nanog-bounces@nanog.org




Using bgplay.routeviews.org/bgplay for my prefixes (also hijacked) it looks like the damage is only to ASs downstream of either (or both) ASN 3130 and/or ASN 2914.

Given the large number of respondents to the thread, it looks like a possible case of no filtering by upstreams and full table announcements/withdrawals over a period of about 40 minutes beginning 23:22 11/10/2008 GMT.  There was also a problem at 17:09:30 2008 GMT for our prefixes.

scott


ps. 

subthread on what's working and how with these prefix hijack alert systems: BGPmon alerted on this and PHAS did not.  They're the only two I am on at this time.  

The 3.5 hour period has not happened for PHAS's damping technique to work.  I have 10 separate emails from BGPmon


home help back first fref pref prev next nref lref last post