Monday 3 April 2017 is not your private network

A recent phishing email originating from an Office 365 caused some confusion.. apparently originating fom an address in the range which according to a WHOIS lookup is the UK's Ministry of Defence.

In this case the connection appeared to come from dm5pr17cu002.internal.outlook.com which does indeed resolve to which would place it in the MoD's address range. Yes?

Well.. no, because the range isn't routable. You can't send traffic to it from the Internet. But it isn't a "private" IP range, it is allocated to the MoD. But it does seem that some companies are taking advantage of this and are using for internal networks (much the same as when it isn't designed for that.

Of course you can make a DNS record point to anything, it doesn't mean that the server will resolve. A look at all the hosts in reveals these apparently active servers:



In the case of the outlook.com servers the DNS has been misconfigured. What should resolve only PRIVATELY to an 25/8 address is resolving PUBLICALLY to an address in that range. Of course, the servers never respond.And note that this is just one /16, not the whole /8 (reverse DNS for the whole /8 is insane).

The upshot is that the MoD get a lot of abuse calls for bad things that people think originate from their network, but it isn't actually happening.

If you are going to use blocks like for internal uses, I would suggest that you take great care not to expose the internal IPs to the outside world. I'm sure the poor people at the MoD would appreciate it.

Unknown said...

You should tell that to the idiots at LogMeIn. Their Hamachi vpn service uses (They moved from in 2004 or something). I don't like it.