Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Virgin Media Internet Service (https://www.cableforum.uk/board/forumdisplay.php?f=12)
-   -   Superhub : Port scan on (https://www.cableforum.uk/board/showthread.php?t=33689290)

Boabyboy 17-08-2012 19:12

Port scan on
 
Within the superhub firewall log, I am getting a port scan showing below:

Date:Fri 17 Aug
Time:19:57
Source IP:194.168.4.100
Target Port Number:58600
Count:27
Event Description:TCP- or UDP-based

Checking ip address reveals this below:
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '194.168.4.0 - 194.168.5.255'

inetnum: 194.168.4.0 - 194.168.5.255
netname: CABLEOL
descr: Cable Online Ltd
country: GB
admin-c: NNMC1-RIPE
tech-c: NNMC1-RIPE
status: ASSIGNED PA
mnt-by: AS5089-MNT
remarks: INFRA-AW
source: RIPE # Filtered

role: NTLI Network Management Centre
address: NTL Internet
address: Test
address: Winchester
address: Hampshire
address: SO21 2QA
phone: +44 1633710142
admin-c: MH22007-RIPE
admin-c: NR731-RIPE
admin-c: CW1083-RIPE
tech-c: MH22007-RIPE
tech-c: CW1083-RIPE
nic-hdl: NNMC1-RIPE
mnt-by: AS5089-MNT
source: RIPE # Filtered

% Information related to '194.168.0.0/16AS5089'

route: 194.168.0.0/16
descr: NTL-UK-IP-BLOCK-1
origin: AS5089
mnt-by: AS5089-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.19.5 (WHOIS4)

Any ideas why would I get port scanned for this?

Thanks,
Boabyboy

mikep 17-08-2012 20:18

Re: Port scan on
 
Thats the DNS server. Probably a false positive from the SH.

Boabyboy 17-08-2012 21:07

Re: Port scan on
 
Cool, so it is nothing to worry about? Just a bit odd to why it would trigger the firewall log today?

General Maximus 20-08-2012 06:29

Re: Port scan on
 
the firewall is pants and this is why you shouldnt use it. If it is flagging good stuff, how much bad stuff is it letting through?

Boabyboy 25-08-2012 05:29

Re: Port scan on
 
God knows, I have no idea? :-(

One Pound 27-08-2012 20:51

Re: Port scan on
 
Quote:

Originally Posted by Boabyboy (Post 35464311)
Event Description:TCP- or UDP-based

That's helpful.


All times are GMT. The time now is 21:31.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum