home tags events about login
one honk maybe more

benjojo posted 06 May 2026 14:49 +0000

Mildly interesting, it seems that one of the name servers for the .de DNS zone has all of their Cogent customers going via CNNIC (China Internet Network Information Center) all the way to China

A traceroute from Cogent in Frankfurt:

traceroute to 194.246.96.1 (194.246.96.1), 30 hops max, 60 byte packets
 1  * *
 2  be5200.ccr41.fra05.atlas.cogentco.com (154.54.76.169)  0.603 ms
 3  be7946.ccr42.par01.atlas.cogentco.com (154.54.72.117)  9.937 ms 
 4  be2780.ccr32.mrs02.atlas.cogentco.com (154.54.72.226)  20.813 ms 
 5  be2899.ccr21.hkg02.atlas.cogentco.com (154.54.0.42)  181.371 ms 
 6  154.18.9.165 (154.18.9.165)  185.283 ms 
 7  159.226.254.229 (159.226.254.229)  220.828 ms 
 8  * *
 9  218.241.107.69 (218.241.107.69)  221.520 ms !X *

Probably a mistake rather than anything malicious, but that's still some extra long haul miles for some DNS queries

A bgp.tools propergation graph that shows 194.246.96.0/24 going via CNNIC AS24151 then to Cogent as it's only path that cogent wants to use

benjojo replied 06 May 2026 14:58 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/B1gTJtTvhJ814pr5xK

I suppose I should check if that is a new thing as of yesterday or not...

Since if it was, then that implies that someone has picked a incredible time to do a intercept/MITM of a large DNS zone where a lot of people were disabling DNSSEC validation for in response to a incident