[nsp-sec] PIM messages from China...

David Freedman david.freedman at uk.clara.net
Fri Feb 22 22:39:43 EST 2008


Have been seeing PIM (proto 103) messages from 220.249.91.115 directed towards some of our colocation customers in the UK

Hoping this just an attempt to exploit the old cisco "blocked" bug (http://www.cisco.com/en/US/products/products_security_advisory09186a00801a34c2.shtml) but would like to draw attention to it in case it is not and something nasty is going on.

AS      | IP               | AS Name
4837    | 220.249.91.115   | CHINA169-BACKBONE CNCGROUP China169 Backbone


Dave.



------------------------------------------------
David Freedman
Group Network Engineering 
Claranet Limited
http://www.clara.net


More information about the nsp-security mailing list