North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Security focus (aka bugtraq) reachability

  • From: Mike Tancsa
  • Date: Fri Sep 13 17:24:14 2002



Thanks to the 2 dozen or so people who have confirmed this for me. I did call the SF people in Calgary early this AM and they just asked that I email them which I did... Perhaps it wasnt clear to them or they were busy with other things. (I emailed their ARIN contact as well last night.) Anyways, if there is anyone from Symantec following this list, it does seem that you cannot connect to hosts in 64.0.0.0/8 from your network in Calgary. I imagine with this OpenSSL worm floating around a lot of admins may be wanting to visit this security site.

---Mike

At 04:07 PM 13/09/2002 -0400, Mike Tancsa wrote:


Can anyone with a host in the IP range of 64.0.0.0/8 confirm if they can connect to the www.securityfocus.com or mail.securityfocus.com ? (i.e. the bugtraq people). I have tried from two separate networks (mine and a totally separate ISP nothing to do with my AS) and both cannot connect from different IP addresses in the 64.0.0.0/8 range. From IP addresses outside of 64/8 its fine. Its as if they dont have ip classless enabled or some rogue firewall rules / routes.

e.g.
quartz# telnet -s 199.212.134.17 www.securityfocus.com 80
Trying 66.38.151.10...
Connected to www.securityfocus.com.
Escape character is '^]'.
^]
telnet> close
Connection closed.
quartz# telnet -s 64.7.128.97 www.securityfocus.com 80
Trying 66.38.151.10...
telnet: connect to address 66.38.151.10: Operation timed out
telnet: Unable to connect to remote host
quartz#

quartz# traceroute -s 199.212.134.17 www.securityfocus.com
traceroute to www.securityfocus.com (66.38.151.10) from 199.212.134.17, 64 hops max, 40 byte packets
1 iolite (209.112.4.3) 1.206 ms 2.952 ms 3.377 ms
2 hespler-waterloo (199.212.135.65) 3.299 ms 0.497 ms 1.419 ms
3 waterloo-hespler (199.212.135.66) 2.839 ms 2.542 ms 1.740 ms
4 tor-wat (64.7.143.42) 8.786 ms 6.523 ms 9.926 ms
5 64.187.3.213 (64.187.3.213) 55.151 ms 49.215 ms 52.673 ms
6 h216-18-62-89.gtconnect.net (216.18.62.89) 53.744 ms 51.485 ms 52.029 ms
7 GE3-1.WANB-TOROON.IP.GROUPTELECOM.NET (216.18.63.13) 51.477 ms 51.297 ms 54.376 ms
8 POS9-2.WANB-CALGAB.IP.GROUPTELECOM.NET (216.18.32.165) 49.236 ms 52.984 ms 51.725 ms
9 216.18.32.6 (216.18.32.6) 52.931 ms 68.631 ms 47.683 ms
10 216.18.37.117 (216.18.37.117) 51.466 ms 51.354 ms 51.815 ms
11 216.18.37.117 (216.18.37.117) 54.124 ms !X *^C
quartz#

They are single homed out of GT (AS 6539).

---Mike
--------------------------------------------------------------------
Mike Tancsa, tel +1 519 651 3400
Sentex Communications, [email protected]
Providing Internet since 1994 www.sentex.net
Cambridge, Ontario Canada www.sentex.net/mike