BGPMON Alert Questions

Zachary McGibbon zachary.mcgibbon+nanog at gmail.com
Wed Apr 2 20:34:50 UTC 2014


Same here:


====================================================================
Possible Prefix Hijack (Code: 10)
====================================================================
Your prefix:          132.206.0.0/16:
Prefix Description:   MCGILL-NET-132-206
Update time:          2014-04-02 20:11 (UTC)
Detected by #peers:   1
Detected prefix:      132.206.0.0/16
Announced by:         AS4761 (INDOSAT-INP-AP INDOSAT Internet Network
Provider,ID)
Upstream AS:          AS4651 (THAI-GATEWAY The Communications Authority of
Thailand(CAT),TH)
ASpath:               18356 38794 4651 4761
Alert details:
https://portal.bgpmon.net/alerts.php?details&alert_id=41664976
Mark as false alert:  https://portal.bgpmon.net/fp.php?aid=41664976

====================================================================
Possible Prefix Hijack (Code: 10)
====================================================================
Your prefix:          142.157.128.0/18:
Prefix Description:   McGill
Update time:          2014-04-02 20:11 (UTC)
Detected by #peers:   1
Detected prefix:      142.157.128.0/18
Announced by:         AS4761 (INDOSAT-INP-AP INDOSAT Internet Network
Provider,ID)
Upstream AS:          AS4651 (THAI-GATEWAY The Communications Authority of
Thailand(CAT),TH)
ASpath:               18356 9931 4651 4761
Alert details:
https://portal.bgpmon.net/alerts.php?details&alert_id=41664977
Mark as false alert:  https://portal.bgpmon.net/fp.php?aid=41664977



On Wed, Apr 2, 2014 at 3:21 PM, Felix Aronsson <felix at mrfriday.com> wrote:

> Seeing the same here for a /21. This seems to have happened before with
> AS4761? See
> http://www.bgpmon.net/hijack-by-as4761-indosat-a-quick-report/from
> january 2011.
>
>
> On Wed, Apr 2, 2014 at 8:51 PM, Joseph Jenkins
> <joe at breathe-underwater.com>wrote:
>
> > So I setup BGPMON for my prefixes and got an alert about someone in
> > Thailand announcing my prefix.  Everything looks fine to me and I've
> > checked a bunch of different Looking Glasses and everything announcing
> > correctly.
> >
> > I am assuming I should be contacting the provider about their
> > misconfiguration and announcing my prefixes and get them to fix it.  Any
> > other recommendations?
> >
> > Is there a way I can verify what they are announcing just to make sure
> they
> > are still doing it?
> >
> > Here is the alert for reference:
> >
> > Your prefix:          8.37.93.0/24:
> >
> > Update time:          2014-04-02 18:26 (UTC)
> >
> > Detected by #peers:   2
> >
> > Detected prefix:      8.37.93.0/24
> >
> > Announced by:         AS4761 (INDOSAT-INP-AP INDOSAT Internet Network
> > Provider,ID)
> >
> > Upstream AS:          AS4651 (THAI-GATEWAY The Communications Authority
> of
> > Thailand(CAT),TH)
> >
> > ASpath:               18356 9931 4651 4761
> >
>



More information about the NANOG mailing list