We're seeing packets with spoofed source addresses destined to 195.238.3.33 getting dropped on firewalls at several locations going outbound. Googling has turned up nothing relating to that destination IP address. Is anyone else seeing this? Anyone know what it is? Thanks, Tim
Went to Nic.com and got this: OrgName: RIPE Network Coordination Centre OrgID: RIPE Address: Singel 258 Address: 1016 AB City: Amsterdam StateProv: PostalCode: Country: NL NetRange: 195.0.0.0 - 195.255.255.255 CIDR: 195.0.0.0/8 NetName: RIPE-CBLK3 NetHandle: NET-195-0-0-0-1 Parent: NetType: Allocated to RIPE NCC NameServer: NS.RIPE.NET NameServer: AUTH03.NS.UU.NET NameServer: NS2.NIC.FR NameServer: SUNIC.SUNET.SE NameServer: MUNNARI.OZ.AU NameServer: NS.APNIC.NET Comment: These addresses have been further assigned to users in Comment: the RIPE NCC region. Contact information can be found in Comment: the RIPE database at whois.ripe.net Comment: RegDate: 1996-03-25 Updated: 1998-10-16 TechHandle: RIPE-NCC-ARIN TechName: RIPE NCC Hostmaster TechPhone: +31 20 535 4444 TechEmail: nicdb@ripe.net OrgTechHandle: RIPE-NCC-ARIN OrgTechName: RIPE NCC Hostmaster OrgTechPhone: +31 20 535 4444 OrgTechEmail: nicdb@ripe.net # ARIN WHOIS database, last updated 2003-02-09 20:00 # Enter ? for additional hints on searching ARIN's WHOIS database. ------------------------------ Information supplied by the registry queried, nic.com makes no warranty or representation of accuracy. Register your COM, NET, ORG, INFO and BIZ domains at http://www.nic.com. Bulger, Tim wrote:
We're seeing packets with spoofed source addresses destined to 195.238.3.33 getting dropped on firewalls at several locations going outbound. Googling has turned up nothing relating to that destination IP address. Is anyone else seeing this? Anyone know what it is?
Thanks, Tim
-- May God Bless you and everything you touch. My "foundation" verse: Isaiah 54:17 No weapon that is formed against thee shall prosper; and every tongue that shall rise against thee in judgment thou shalt condemn. This is the heritage of the servants of the LORD, and their righteousness is of me, saith the LORD.
On Mon, Feb 10, 2003 at 12:05:55PM -0800, Bulger, Tim wrote:
We're seeing packets with spoofed source addresses destined to 195.238.3.33 getting dropped on firewalls at several locations going outbound. Googling has turned up nothing relating to that destination IP address.
inetnum: 195.238.0.0 - 195.238.31.255 netname: SKYNET-B descr: Belgacom Skynet SA/NV descr: Internet access provider descr: A subsidiary of BELGACOM SA/NV country: BE route: 195.238.0.0/19 descr: Belgacom Skynet SA/NV origin: AS5432 notify: noc@skynet.be $ host irc.skynet.be irc.skynet.be. is an alias for chick.skynet.be. chick.skynet.be. has address 195.238.0.13 Well, close... :-P You might want to contact noc@skynet.be... Regards, Daniel
On Mon, Feb 10, 2003 at 12:05:55PM -0800, Bulger, Tim wrote:
We're seeing packets with spoofed source addresses destined to 195.238.3.33 getting dropped on firewalls at several locations going outbound. Googling has turned up nothing relating to that destination IP address. Is anyone else seeing this? Anyone know what it is?
Thanks, Tim
This should help
server ns1.skynet.be Default Server: ns1.skynet.be Address: 195.238.3.17
195.238.3.33 Server: ns1.skynet.be Address: 195.238.3.17
Name: userspool1.skynet.be Address: 195.238.3.33
participants (4)
-
Bulger, Tim
-
Daniel Roesen
-
Martin Hannigan
-
William Warren