Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: nsp: ipv6

Active ipv6 'mapping' project ?

 

 

nsp ipv6 RSS feed   Index | Next | Previous | View Threaded


brandon at burn

Jul 27, 2011, 1:18 PM

Post #1 of 3 (491 views)
Permalink
Active ipv6 'mapping' project ?

Just poking around in my home firewall logs. I have a tunnel to one of my
data centers giving the house ipv6. I noticed a steady flow of icmp echo
requests with the destination address being my firewall itself. This
pattern is steady (not a flood, but it is constant). They are all 64 byte
packets with the payload being the typical walk through ASCII.

A sample of the source addresses are here:

http://pastebin.com/X9FwBtkE

That's from ~ 1000 packets sample. A good amount of these come back as
Akamai.

Anyone know what this is ? Thanks.

--
Brandon Applegate - CCIE 10273
PGP Key fingerprint:
7407 DC86 AA7B A57F 62D1 A715 3C63 66A1 181E 6996
"SH1-0151. This is the serial number, of our orbital gun."


jeroen at unfix

Jul 27, 2011, 1:29 PM

Post #2 of 3 (465 views)
Permalink
Re: Active ipv6 'mapping' project ? [In reply to]

On 2011-07-27 22:18 , Brandon Applegate wrote:
> Just poking around in my home firewall logs. I have a tunnel to one of
> my data centers giving the house ipv6. I noticed a steady flow of icmp
> echo requests with the destination address being my firewall itself.
> This pattern is steady (not a flood, but it is constant). They are all
> 64 byte packets with the payload being the typical walk through ASCII.
>
> A sample of the source addresses are here:
>
> http://pastebin.com/X9FwBtkE
>
> That's from ~ 1000 packets sample. A good amount of these come back as
> Akamai.
>
> Anyone know what this is ? Thanks.

As the sources are mostly in backbone networks have you thought about
somebody running an 'mtr' which does a per-hop ICMP request continuesly?

But those would be echo responses on your side then not requests.

The "walk through ASCII" sounds like a normal ping at least and could
quite well be either fping or mtr too.

If you can provide a packet dump of at least one of these packets
(scrubbing src/dst if you want) that would help.

One big question of course is if your 'dst' address (the 'firewall') is
published anywhere or not.

Greets,
Jeroen


brandon at burn

Jul 27, 2011, 1:36 PM

Post #3 of 3 (471 views)
Permalink
Re: Active ipv6 'mapping' project ? [In reply to]

On Wed, 27 Jul 2011, Jeroen Massar wrote:

> On 2011-07-27 22:18 , Brandon Applegate wrote:
>> Just poking around in my home firewall logs. I have a tunnel to one of
>> my data centers giving the house ipv6. I noticed a steady flow of icmp
>> echo requests with the destination address being my firewall itself.
>> This pattern is steady (not a flood, but it is constant). They are all
>> 64 byte packets with the payload being the typical walk through ASCII.
>>
>> A sample of the source addresses are here:
>>
>> http://pastebin.com/X9FwBtkE
>>
>> That's from ~ 1000 packets sample. A good amount of these come back as
>> Akamai.
>>
>> Anyone know what this is ? Thanks.
>
> As the sources are mostly in backbone networks have you thought about
> somebody running an 'mtr' which does a per-hop ICMP request continuesly?
>
> But those would be echo responses on your side then not requests.
>
> The "walk through ASCII" sounds like a normal ping at least and could
> quite well be either fping or mtr too.
>
> If you can provide a packet dump of at least one of these packets
> (scrubbing src/dst if you want) that would help.
>
> One big question of course is if your 'dst' address (the 'firewall') is
> published anywhere or not.
>
> Greets,
> Jeroen
>

I think I figured it out. I ran curl against the list and they are all
"Akamai GHost" servers on port 80. My firewall also runs bind and
therefore all the devices here trying their various updates are hitting
Akamai'zed services. I guess they are trying to get stats on latency to
the DNS server (which is my firewall).

I just didn't think it would be so constant.

I found this as well:

http://support.akamai.com/cgi-public/cease-pinging.cgi?id=134

Looks fairly dated, wonder if it does anything.

Anyway, sorry for the noise and thanks for feedback. Unless someone from
Akamai sees this and can give me a bit more clue as to what's going on - I
think I will try to send them an email directly.

nsp ipv6 RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.