[talk] I am bored sitting in a Burger King, so of course I join the Wi-Fi and play around .

Anthony Elizondo anthony.elizondo at gmail.com
Sun Oct 9 20:24:59 EDT 2022


On Sun, Oct 9, 2022 at 5:08 PM Mark Saad <nonesuch at longcount.org> wrote:

> So like I said, I am bored sitting in a Burger King and they have free
> Wi-Fi . It a fortinet captive portal on optimum cable internet . However a
> tracer out shows this .
>
>
> #1
> - RTT [ms]: 2.7
> - Probe Send Time: 4:30:50 PM
> - IP Address: 192.168.20.254
> - TTL: 255
>
> #2
> - RTT [ms]: 2.9
> - Probe Send Time: 4:30:50 PM
> - IP Address: 223.255.0.2
> - TTL: 254
> - Country Name: China
> - Country Code: CN
> - Time Zone: Asia/Shanghai
>
> #3
> - Probe Send Time: 4:30:51 PM
>
> #4
> - RTT [ms]: 12.2
> - Probe Send Time: 4:30:54 PM
> - IP Address: 67.59.255.241
> - TTL: 252
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #5
> - RTT [ms]: 11.9
> - Probe Send Time: 4:30:54 PM
> - IP Address: 167.206.32.6
> - Hostname: dstswr2-ge3-1.rh.hcvlny.cv.net
> - TTL: 251
> - AS Number: AS6128
> - AS Name: CABLE-NET-1
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/New_York
> - Region: NY
> - City: New Rochelle
> - Latitude: 40.92
> - Longitude: -73.79
>
> #6
> - RTT [ms]: 15.0
> - Probe Send Time: 4:30:54 PM
> - IP Address: 64.15.4.134
> - TTL: 248
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #7
> - RTT [ms]: 16.1
> - Probe Send Time: 4:30:54 PM
> - IP Address: 64.15.1.88
> - TTL: 249
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #8
> - RTT [ms]: 16.4
> - Probe Send Time: 4:30:54 PM
> - IP Address: 72.14.215.203
> - TTL: 244
> - AS Number: AS15169
> - AS Name: GOOGLE
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #9
> - Probe Send Time: 4:30:55 PM
>
> #10
> - RTT [ms]: 29.3
> - Probe Send Time: 4:30:58 PM
> - IP Address: 142.251.65.110
> - TTL: 54
> - AS Number: AS15169
> - AS Name: GOOGLE
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #11
> - RTT [ms]: 20.8
> - Probe Send Time: 4:30:59 PM
> - IP Address: 108.170.248.116
> - TTL: 246
> - AS Number: AS15169
> - AS Name: GOOGLE
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #12
> - RTT [ms]: 14.6
> - Probe Send Time: 4:30:59 PM
> - IP Address: 142.251.40.174
> - Hostname: google.com
> - TTL: 245
> - AS Number: AS15169
> - AS Name: GOOGLE
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> #13
> - RTT [ms]: 14.9
> - Probe Send Time: 4:30:59 PM
> - IP Address: 142.251.40.174
> - Hostname: google.com
> - TTL: 115
> - AS Number: AS15169
> - AS Name: GOOGLE
> - Country Name: United States
> - Country Code: US
> - Time Zone: America/Chicago
>
> My external ip is 68.196.104.162 . So it looks like my second hop is a ip
> allocated to bytedance , in china ? So is this some weird tictok crap ?
>
> Thoughts ?
>

Looks like Fortinet devices use 223.X for internal services. See
https://www.fortinetguru.com/2017/03/fortiwan-dns-proxy/
223/8 was assigned to APNIC and started to be used in 2010. Prior to that I
think it was UNALLOCATED.
https://www.iana.org/reports/2008/sample-ipv4-address-space.xhtml
Another instance of using IP space that isn't yours, I guess.

Anthony


> ---
> Mark Saad | nonesuch at longcount.org
> _______________________________________________
> talk mailing list
> talk at lists.nycbug.org
> https://lists.nycbug.org:8443/mailman/listinfo/talk
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.nycbug.org:8443/pipermail/talk/attachments/20221009/698becb0/attachment.htm>


More information about the talk mailing list