[179043] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: Prefix hijack by INDOSAT AS4795 / AS4761

daemon@ATHENA.MIT.EDU (Peter Rocca)
Thu Mar 26 10:43:34 2015

X-Original-To: nanog@nanog.org
From: Peter Rocca <rocca@start.ca>
To: "nanog@nanog.org" <nanog@nanog.org>
Date: Thu, 26 Mar 2015 14:43:20 +0000
In-Reply-To: <b8636bc52cdc7f7f595ff96c7b078445@mailbox.fastserv.com>
Errors-To: nanog-bounces@nanog.org

We just received a similar alert from bgpmon - part of 108.168.0.0/17 is be=
ing advertised as /20's - although we're still listed as the origin. We are=
 40788.

108.168.64.0/20  4795 4795 4761 9304 40633 18978 6939 40788
108.168.80.0/20  4795 4795 4761 9304 40633 18978 6939 40788
108.168.96.0/20  4795 4795 4761 9304 40633 18978 6939 40788
108.168.112.0/20 4795 4795 4761 9304 40633 18978 6939 40788

-----Original Message-----
From: NANOG [mailto:nanog-bounces@nanog.org] On Behalf Of Randy
Sent: March-26-15 10:08 AM
To: nanog@nanog.org
Subject: Prefix hijack by INDOSAT AS4795 / AS4761

On Thursday March 26th 2015 at 12:18 UTC (and on-going) we are seeing=20
more specifics on one of our prefixes.   Anyone else seeing similar or=20
is it just us?

198.98.180.0/23	4795 4795 4761 9304 40633 18978 4436 29889
198.98.182.0/23	4795 4795 4761 9304 40633 18978 4436 29889

--=20
Randy

home help back first fref pref prev next nref lref last post