who_is_using_this_ip_address
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
who_is_using_this_ip_address [2014/02/08 22:06] – samer | who_is_using_this_ip_address [2014/02/08 22:45] – samer | ||
---|---|---|---|
Line 10: | Line 10: | ||
origin: | origin: | ||
- | However things get complicated very rapidly since the route object information is not always provided or may be outdated. Trying for example to identify the AS announcing 203.178.141.194 (corresponding to the famous www.kame.net), | + | However things get complicated very rapidly since the route object information is not always provided or may be outdated. Trying for example to identify the AS announcing |
$ whois -h whois.apnic.net 203.178.141.194 | grep origin | $ whois -h whois.apnic.net 203.178.141.194 | grep origin | ||
Line 21: | Line 21: | ||
However, having access to a DFZ BGP router is not easy in practice. Alternatively, | However, having access to a DFZ BGP router is not easy in practice. Alternatively, | ||
- | Let us try for example to log on the Allstream route server in Canada and identify the origin AS of 148.60.0.0/ | + | Let us try for example to log on the Allstream route server in Canada and identify the origin AS of '' |
$ telnet route-server.east.bb.allstream.net | $ telnet route-server.east.bb.allstream.net | ||
Line 45: | Line 45: | ||
Community: 15290:3356 15290:64995 15290:65050 15290:65506 | Community: 15290:3356 15290:64995 15290:65050 15290:65506 | ||
- | Despite its availability, | + | Despite its availability, |
- | | + | ==== -- Team Cymru whois Server ==== |
- | - A similar service was announced by the RIPE RIS project. Their whois server can be queried using '' | + | Team Cymru implements |
+ | |||
+ | < | ||
+ | $ whois -h whois.cymru.com 148.60.0.0/ | ||
+ | AS | IP | AS Name | ||
+ | 2200 | 148.60.0.0 | ||
+ | </ | ||
+ | |||
+ | and another example that demonstrates the possibility of sending multiple addresses | ||
+ | |||
+ | < | ||
+ | $ whois -h whois.cymru.com 148.60.0.0/ | ||
+ | AS | IP | AS Name | ||
+ | 2200 | 148.60.0.0 | ||
+ | AS | IP | AS Name | ||
+ | 2500 | 203.178.141.194 | ||
+ | </ | ||
+ | |||
+ | ==== -- Riswhois Server ==== | ||
+ | RIPE NCC implements a similar | ||
+ | |||
+ | <WRAP info> | ||
+ | As mentioned on the [[http:// | ||
+ | </ | ||
+ | |||
+ | In the following, a simple example that shows the output of a riswhois query. | ||
$ whois -h riswhois.ripe.net 217.70.180.132 | $ whois -h riswhois.ripe.net 217.70.180.132 | ||
Line 84: | Line 109: | ||
num-rispeers: | num-rispeers: | ||
source: | source: | ||
- | |||
===== -- A Do-It-Yourself BGP Query Service ===== | ===== -- A Do-It-Yourself BGP Query Service ===== | ||
Start by downloading multiple routing tables for routeviews or RIPE RIS servers. Transform these tables into parsable format bu using bgpdump. Use any scripting language to perform a best prefix match and output the origin AS of your desired IP prefix. | Start by downloading multiple routing tables for routeviews or RIPE RIS servers. Transform these tables into parsable format bu using bgpdump. Use any scripting language to perform a best prefix match and output the origin AS of your desired IP prefix. |
who_is_using_this_ip_address.txt · Last modified: 2014/02/15 23:31 by samer