AS16387 leaking routes
morrowc.lists at gmail.com
Mon Feb 15 22:46:18 UTC 2010
On Mon, Feb 15, 2010 at 5:32 PM, Ernest Andrew McCracken (emccrckn)
<emccrckn at memphis.edu> wrote:
> Has anyone seen the strange activity from AS16387? Did they leak their entire table? Our route collectors are showing AS16387 originating large numbers of prefixes. It looks like we caught the tail end of this activity as they are now announcing updates with massive amounts of prepending.
16387 is a uunet customer, it seems, who's only annoucing (now) 2
prefixes... Robtex seems to support them only having a single upstream
(701). I think 701 still prefix-lists all their customers.
You saw this through 3303 without 701 (it seems?) in the path, The
orignal prefix looks actually like 220.127.116.11/19 in the path: 34533
that looks like ESamara trying to poison their paths toward 'healthy
maybe ESamara saw something they disliked from this part of the network?
More information about the NANOG