You are here: Home > Participate > Join a Discussion > RIPE Forum
RIPE Forum v1.4.1

Anti-Abuse Working Group

Threaded
Collapse

[anti-abuse-wg] AS47860 - 93.175.240.0/20 (redux)

Ronald F. Guilmette

2016-10-08 22:53:58 CET

Online records seem to suggest that the bogus unregistered AS47860
is and always was just a property of the one and only entity that
is providing it with route distribution, i.e. AS43659, D2 International
Investment Ukraine, Ltd.

http://1whois.ru/world/UA/%D0%9A%D0%B8%D0%B5%D0%B2/LLC%20%22Albino%22
(Note the abuse email address.)

Note that AS43659, D2 International Investment Ukraine, Ltd. is itself
an authorized RIPE NCC LIR:

https://www.ripe.net/membership/indices/data/ua.d2investukraine.html

I have already written to that organization via the following two
email addresses and I have received no reply:

    support _at_ etthua _dot_ net, d2invest _at_ meta _dot_ ua

Could someone who actually speaks Ukranian please email these crooks and
ask them nicely to stop passing routes for unregistered IPv4 space?


Regards,
rfg


P.S.  Looking over this document:

     https://www.ripe.net/publications/docs/ripe-640

It appears to me to be the case that it is possible to become a full
fledged dues-paying RIPE NCC LIR member while having never made any
sort of pledge whatsoever to refrain from announcing routes to IP space
for which the member has no clear rights, either directly, from the
relevant RIR, or indirectly from that actual registrant.  Is that
correct?

Forgive me.  Even after all this time, I'm still trying to wrap my
head around this charade, this farce.  RIPE NCC makes, creates, and
provides allocations, but then never formally asks any of its members
to respect or obey any of those.  Is that about the size of it?

User Image

David Hilario

2016-10-10 11:21:50 CET


Hi Ronald,

I hope the following helps you a bit.

1)
The noise you made seem to have been successful, the AS is not in use anymore:

https://stat.ripe.net/AS47860#tabId=routing

Congrats!


2)
A quick search on the AS itself in google gives you a website with a snapshot of the RIPE DB information:

http://www.tcpiputils.com/browse/as/47860
So unless that website fabricated the objects, you can safely assume that this AS number was registered to LLC "Albino" and not a rogue for "years", it was registered to an entity from 2008 to at least until late 2015, I unfortunately cannot say when it was de-registered:


aut-num: AS47860 
as-name: Albino-ua-as 
org: ORG-LA176-RIPE 
admin-c: SSI26-RIPE 
tech-c: OPS3-RIPE 
status: ASSIGNED 
mnt-by: RIPE-NCC-END-MNT 
mnt-by: ALBINO2-MNT 
mnt-routes: ALBINO2-MNT 
created: 2008-09-05T15:27:31Z 
last-modified: 2015-10-06T11:23:12Z 
source: RIPE # Filtered


organisation: ORG-LA176-RIPE 
org-name: LLC "Albino" 
org-type: OTHER 
address: Ukraine, Kiev 02092 Makarenko st. 5 
abuse-c: AR25136-RIPE 
phone: +380 63 678 80 12 
admin-c: SSI26-RIPE 
tech-c: OPS3-RIPE 
mnt-ref: ALBINO-MNT 
mnt-by: ALBINO-MNT 
abuse-mailbox:  removed email address 
created: 2008-08-13T12:52:24Z 
last-modified: 2014-11-17T21:01:41Z 
source: RIPE # Filtered 


The AS number shows no sponsoring LIR in that snapshot and since was it registered to an end-user it is required to have one in order to be kept by its holder.
Resources like that need to find a new sponsoring LIR or the holder needs to become an LIR or they will be de-registered by the RIPE NCC.


Since it is not present in the RIPE Database anymore, you know that the RIPE NCC de-registered it. 
Only the RIPE NCC can de-register independent resources from the RIPE Database.

So the RIPE NCC did what they had to do, why it could not be sponsored again/anymore is up to anyone's guess, it could even had been returned by the end-user itself, that info cannot be disclosed publicly by the RIPE NCC unfortunately.

Now as to why it was still being announced by that LIR, this is something else, and only that LIR can answer you.


In general, the RIPE NCC cannot control what is being announced by LIRs, incorrect announcements are common place and most often than not result of outdated info/config or typos, purposefully announcing resources is wrong, bad netiquette you can say and indicative of malicious intent when repeated, but AFAIK it cannot be flagged as policy violation and out of scope from the RIPE NCC's work at the moment without being backed up by a policy.


Of course a policy to define the actions that the RIPE NCC can take in such case could be submitted here as part of a RIPE Working group.

The reporting can also be automated, you could have RIPE Stat showing AS number or any related objects in "red" or with a pirate flag (personal preference) when announcing or peering with unregistered resources this would probably not require a policy and would be a fully automated service, but I don't think the pirate flag would make it though though.

Anyone interested could get this info out in bulk directly from the NCC or even receive notifications that something is at odd and either work on not peering with such networks or fix their own network if they ended up being in the list due to outdated config or typos. 

It would be a bit of an overlap of the info already provided by Geoff Huston though:
http://www.cidr-report.org/as2.0/#Bogons


And as always, good guys would fix their things, bad guys would simply enjoy having a pirate flag!
Cheers,
David Hilario