North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Interesting Announcements

  • From: Roland Verlander
  • Date: Sat May 03 04:13:40 2003

[email protected] wrote:
> Anyone know why AS 8143:
> $ whois -h whois.arin.net 8143
> 
> OrgName:    Publicom Corp.
> OrgID:      PUBLIC-35
> Address:    1450 Coral Way #10
> City:       Miami
> StateProv:  FL
> PostalCode: 33145
> Country:    US
> RegDate:    1997-04-25
> 
> Is announcing the following blocks?
>
> $ whois -h whois.arin.net 155.73.0.0
> OrgName:    Borealis AS
> 
> $ whois -h whois.arin.net 134.33.0.0
> 
> OrgName:    Codex Corporation

In that case, the hijacker setup a fake webhost
that It's impossible to signup for at
http://www.codexcorp.net [134.33.0.7] to make
them look legitimate.

> $ whois -h whois.arin.net 196.4.167.0                            
> 
> OrgName:    Juta Information Network
>
> $ whois -h whois.arin.net 144.2.0.0                              
> 
> OrgName:    Publico B.V.
>
> $ whois -h whois.arin.net 143.49.160.0                           
> OrgName:    Inform, Ltd.
> 
> $ whois -h whois.arin.net 160.116.160.0                          
> OrgName:    Affiliated Computing Services (Pty) Ltd
>
> $ whois -h whois.arin.net 162.73.128.0                           
> OrgName:    Information Technology
> 
> $ whois -h whois.arin.net 198.204.0.0                            
> OrgName:    GHR Services Inc.

Thier all hijacked netblocks.

> Also,
> Perhaps someone from AS16631 (Cogent) can explain this one:
> 
> Why is AS27255:
> $ whois -h whois.arin.net 27255                                  
> 
> OrgName:    VMX Inc
> 
> Announcing this?
> 
> $ whois -h whois.arin.net 157.156.0.0                            
> 
> OrgName:    VMX Inc
> RegDate:    1992-01-13

Another hijacked one.

> Had a /16 for 11 years, just recently decided to get an ASN? Seems like
> someone just registered a new company to have the same name as a company
> that had a /16, and then got a new ASN....

No. Thier just hijacked netblocks.

Tower Group who had thier unused netblocks been
announced by AS8143 confirmed that it was hijacked.