[139247] in North American Network Operators' Group
Re: HIJACKED: 148.163.0.0/16 -- WTF? Level3 is now doing IP
daemon@ATHENA.MIT.EDU (Tony Tauber)
Thu Mar 31 11:34:24 2011
In-Reply-To: <AANLkTinuDpR-KRMYKmvf6_BQG6dCMHW=s6oQUSabs_yM@mail.gmail.com>
Date: Thu, 31 Mar 2011 11:33:25 -0400
From: Tony Tauber <ttauber@1-4-5.net>
To: Christopher Morrow <morrowc.lists@gmail.com>
Cc: "nanog@nanog.org" <nanog@nanog.org>, Brandon Ross <bross@pobox.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
I don't believe this record indicates that Level3 proxy registered the route
object.
It means that someone used the DBANK-MNT maintainer ID in the Level3 RR to
enter a route object 18 months ago.
It looks like Level3 is originating the route in AS3356, not accepting it
from AS13767 (which is what the object would suggest to do.)
Oops, looks like the route is now gone. Guess it got cleaned.
Tony
On Thu, Mar 31, 2011 at 5:49 AM, Christopher Morrow <morrowc.lists@gmail.com
> wrote:
>
> I forgot:
> $ whois -h whois.radb.net 148.163.0.0
> route: 148.163.0.0/16
> descr: /16 for Celanese
> origin: AS13767
> mnt-by: DBANK-MNT
> changed: jpope@databank.com 20090818
> source: LEVEL3
>
> (this means l3 proxy'd in the record, I think... maybe an L3 person
> can speak to this bit?)
>
> > -chris
> > (being able to validate 'ownership', really authorization to route,
> > automatically will sure be nice, eh?)
> >
>
>