Skip to Content
[CAIDA - Center for Applied Internet Data Analysis logo]
Center for Applied Internet Data Analysis
Session Report

Test run at: 2017-09-19 10:28:06 GMT
Client Prefix (v4): 79.98.78.x/24
Client AS (v4): 44002 (SYS-DATACOM)
IPv4 Probes: 116
Client Prefix (v6): 2a02:970:ffxx::/40
Client AS (v6): 44002 (SYS-DATACOM)
IPv6 Probes: 77

Egress spoofing summary
Address type IPv4IPv6
Private rewrittenreceived
Routable blockedreceived
Largest spoofable neighbor prefix /21/16

Warnings:

  • Your host is behind a Network Address Translation (NAT) router or firewall which rewrites the source addresses of the test traffic. To test your provider's network further, you must remove the NAT/firewall/router and connect directly.

    IPv4 AS Route:

    This test run probed the following paths in order to infer your ability to send different spoofed source packets. Each node in the graph corresponds to an autonomous system, i.e. different Internet service providers. NOTE: This graph does NOT show if an AS blocks spoofed packets, only the path taken by received spoofed packets. The IP Path Details are available for this run.
    
    

    IPv4 Adjacent Netblock Testing:

    Your host (79.98.78.x/24) can spoof 2047 neighboring addresses (within your /21 prefix)


    Spoofed IP (anon)Prefix
    Length
    ASN of
    Spoofed IP
    Received
    79.98.78.x/24/3144002yes
    79.98.78.x/24/3044002yes
    79.98.78.x/24/2944002yes
    79.98.78.x/24/2844002yes
    79.98.78.x/24/2744002yes
    79.98.78.x/24/2644002yes
    79.98.78.x/24/2544002yes
    79.98.78.x/24/2444002yes
    79.98.79.x/24/2344002yes
    79.98.76.x/24/2244002yes
    79.98.74.x/24/2144002yes
    79.98.70.x/24/20198153natblock
    79.98.94.x/24/1912714natblock
    79.98.110.x/24/18197216natblock
    79.98.14.x/24/1744020natblock
    79.98.206.x/24/1642408natblock
    79.99.78.x/24/1531270natblock
    79.96.78.x/24/1412824natblock
    79.102.78.x/24/132119natblock
    79.106.78.x/24/1242313natblock
    79.114.78.x/24/118708natblock
    79.66.78.x/24/109105natblock
    79.34.78.x/24/93269natblock
    79.226.78.x/24/83320natblock

    Meaning of status in Received column:

    yesPackets spoofed from adjacent netblock were received (but that netblock is within the source AS)
    natblockSpoofed probe packets appear to be blocked by your local NAT or firewall rather than being rewritten with a public source address.

    IPv4 Egress Filtering Depth:

    The tracefilter test found your host unable to spoof routable, non-adjacent source addresses through even the first IP hop.
    IPv6 probes:
    Spoofed IPDestinationReceived
    2001:4978:1fb:6400::d22001:388:1:5001:21c:c0ff:fea2:4a3ayes
    2001:49aa:111:aa00::112001:388:1:5001:21c:c0ff:fea2:4a3ayes
    fd11:1111:1111::11112001:388:1:5001:21c:c0ff:fea2:4a3ayes
    2001:4978:1fb:6400::d22001:410:102:1::78yes
    2001:49aa:111:aa00::112001:410:102:1::78yes
    fd11:1111:1111::11112001:410:102:1::78yes
    2001:4978:1fb:6400::d22001:410:90ff::5yes
    2001:49aa:111:aa00::112001:410:90ff::5yes
    fd11:1111:1111::11112001:410:90ff::5yes
    2001:4978:1fb:6400::d22001:48d0:101:501::242yes
    2001:49aa:111:aa00::112001:48d0:101:501::242yes
    fd11:1111:1111::11112001:48d0:101:501::242yes
    2001:4978:1fb:6400::d22001:48d0:101:501::247yes
    2001:49aa:111:aa00::112001:48d0:101:501::247yes
    fd11:1111:1111::11112001:48d0:101:501::247yes
    2001:4978:1fb:6400::d22001:610:510:115:192:42:115:98yes
    2001:49aa:111:aa00::112001:610:510:115:192:42:115:98no
    fd11:1111:1111::11112001:610:510:115:192:42:115:98no
    2001:4978:1fb:6400::d22001:630:212:225:225:90ff:fe0c:45a6yes
    2001:49aa:111:aa00::112001:630:212:225:225:90ff:fe0c:45a6no
    fd11:1111:1111::11112001:630:212:225:225:90ff:fe0c:45a6no
    2001:4978:1fb:6400::d22001:708:40:2001:21c:c0ff:fea2:4c5cyes
    2001:49aa:111:aa00::112001:708:40:2001:21c:c0ff:fea2:4c5cyes
    fd11:1111:1111::11112001:708:40:2001:21c:c0ff:fea2:4c5cno
    2001:4978:1fb:6400::d22001:770:18:7:225:90ff:fe0c:acb4yes
    2001:49aa:111:aa00::112001:770:18:7:225:90ff:fe0c:acb4yes
    fd11:1111:1111::11112001:770:18:7:225:90ff:fe0c:acb4yes
    IPv6 Adjacent Netblock Testing:
    Spoofed IP (anon)Prefix
    Length
    ASN of
    Spoofed IP
    Received
    2a02:970:ffxx::/40/12044002yes
    2a02:970:ffxx::/40/11244002yes
    2a02:970:ffxx::/40/10444002yes
    2a02:970:ffxx::/40/9644002yes
    2a02:970:ffxx::/40/8844002yes
    2a02:970:ffxx::/40/8044002yes
    2a02:970:ffxx::/40/7244002yes
    2a02:970:ffxx::/40/6444002yes
    2a02:970:ffxx::/40/5644002yes
    2a02:970:ffxx::/40/4844002yes
    2a02:970:ffxx::/40/4044002yes
    2a02:970:7fxx::/40/3244002yes
    2a02:9f0:ffxx::/40/24UNROUTEDyes
    2a02:8970:ffxx::/40/16UNROUTEDyes

    Meaning of status in Received column:

    yesPackets spoofed from adjacent netblock were received
    yesPackets spoofed from adjacent netblock were received (but that netblock is within the source AS)
    Summary:
    The results from all tests are aggregated to produce a summary "State of IP Spoofing" report.
    Feedback:
    We welcome questions and feedback to the Spoofer Information Mailing List and invite users to join the Spoofer Users Mailing List for discussion and announcements.
      Last Modified: