[120079] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: AT&T blocking individual IP addresses

daemon@ATHENA.MIT.EDU (Scott Howard)
Wed Dec 9 11:03:47 2009

In-Reply-To: <6065F302-7CA0-4CB7-A26C-41C41BE760E1@arbor.net>
Date: Wed, 9 Dec 2009 08:03:01 -0800
From: Scott Howard <scott@doc.net.au>
To: "Dobbins, Roland" <rdobbins@arbor.net>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

On Wed, Dec 9, 2009 at 7:25 AM, Dobbins, Roland <rdobbins@arbor.net> wrote:

> > Traceroute to the neighboring IP addresses don't go anywhere near the
> above path, so it's apparently a blackhole of sorts.
>
> Are they bots or C&C servers, or open DNS recursors?
>

They are (authenticated-required) proxy servers with 10's of thousands of
users behind them, so it's possible that they were seeing some bot-like
traffic from them, although the volume would have been tiny compared to the
volume of legitimate traffic.

  Scott.

home help back first fref pref prev next nref lref last post