Re: 10.0.1.* alias blackhole-1.iana.org alias 192.175.48.6 ???

From: Barry Margolin (barry.margolin_at_level3.com)
Date: 05/27/03


Date: Tue, 27 May 2003 16:06:06 GMT

In article <banjb3$1k2pp$1@ID-32226.news.dfncis.de>, jx <jx@noplace.com> wrote:
>>>It's not clear (to me, anyway) whether the original poster was trying
>>>to trace to an address on network 10.0.0.0, or to this 192.175.48.6
>>>address that he mentioned. Certainly from any network that I'm
>>>familiar with, trying to trace to a 10.0.0.0 address would not get
>>>very far at all
>
>actually, what I was trying to do was identify the origional
>common source so I could filter it out. This would also, I
>hope, provide a starting point to report to my ISP. It appears to me
>that the 10.0.* ip's are the origional senders, but I
>could be wrong. I'm no expert in header interpretation. I'm
>trying to pick this stuff up as I go along.

10.x.x.x addresses are not unique, and often vary over time for the same
system. So trying to use them as identifying information is usually a
waste of time.

If you want to create filters based on Received headers, skip over the ones
with RFC 1918 networks in them.

-- 
Barry Margolin, barry.margolin@level3.com
Level(3), Woburn, MA
*** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups.
Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.


Relevant Pages

  • Re: 10.0.1.* alias blackhole-1.iana.org alias 192.175.48.6 ???
    ... trying to trace to a 10.0.0.0 address would not get ... common source so I could filter it out. ... that the 10.0.* ip's are the origional senders, ... I'm no expert in header interpretation. ...
    (comp.security.misc)
  • Re: [Full-disclosure] what can be done with botnet C&Cs?
    ... what can be done with botnet C&C's? ... where in order to filter networks. ... QoS and traffic limiting tools. ...
    (Full-Disclosure)
  • Re: BGP partial routes
    ... match as-path 100 ... OBTW you should requet that your ISP only advertise partials to you so ... Also make sure to filter for you own networks in the inbound filters ... Good pt about filtering out our networks. ...
    (comp.dcom.sys.cisco)
  • Re: [Full-Disclosure] cyberwar against US ?
    ... the last two attempts were rejected by some lousy ... filter. ... >> There is networks, no US or Europe or anything on the net. ...
    (Full-Disclosure)
  • Re: BGP partial routes
    ... remember to entering Ctrl-V before entering the? ... OBTW you should requet that your ISP only advertise partials to you so ... Also make sure to filter for you own networks in the inbound filters ...
    (comp.dcom.sys.cisco)