[nsp-sec] PIM messages from China...
David Freedman
david.freedman at uk.clara.net
Fri Feb 22 22:39:43 EST 2008
Have been seeing PIM (proto 103) messages from 220.249.91.115 directed towards some of our colocation customers in the UK
Hoping this just an attempt to exploit the old cisco "blocked" bug (http://www.cisco.com/en/US/products/products_security_advisory09186a00801a34c2.shtml) but would like to draw attention to it in case it is not and something nasty is going on.
AS | IP | AS Name
4837 | 220.249.91.115 | CHINA169-BACKBONE CNCGROUP China169 Backbone
Dave.
------------------------------------------------
David Freedman
Group Network Engineering
Claranet Limited
http://www.clara.net
More information about the nsp-security
mailing list