Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Linksys WCG200 Cable Modem/Router

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

NTL Security probe
Reply
 
Thread Tools
Old 01-07-2004, 21:45   #1
Matth
Inactive
 
Join Date: Mar 2004
Services: BB:M, TV:XL, Phone:M, Loyalty
Posts: 2,516
Matth has reached the bronze age
Matth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze age
NTL Security probe

www.security.scanner.ntli.net - 62.253.160.70

Got scanned twice today:
Ports 2745, 3127, 420, 5000, SMTP (25)
I don't recognize 420, though the others are frequently part of a virus/worm probe

http://www.ntl-isp.ntl.com/ServiceSt...spx?FaultID=90

Nice to know they're being pro-active, and don't waste time reporting the address to NTL, Dshield or Mynetwatchman
Matth is offline   Reply With Quote
Advertisement
Old 01-07-2004, 21:54   #2
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: NTL Security probe

Quote:
Originally Posted by Matth
www.security.scanner.ntli.net - 62.253.160.70

Got scanned twice today:
Ports 2745, 3127, 420, 5000, SMTP (25)
I don't recognize 420, though the others are frequently part of a virus/worm probe

http://www.ntl-isp.ntl.com/ServiceSt...spx?FaultID=90

Nice to know they're being pro-active, and don't waste time reporting the address to NTL, Dshield or Mynetwatchman
420 is SMTPE. nice that they are now including security.scanner for the DNS lookup, they must have got fed up with all the abuse reports.
iadom is offline   Reply With Quote
Old 01-07-2004, 23:55   #3
altis
Inactive
 
altis's Avatar
 
Join Date: Jun 2003
Location: Warrington ntl:81304 Altitude: 12m (and falling)
Posts: 4,499
altis has a nice shiny staraltis has a nice shiny star
altis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny star
Re: NTL Security probe

Oh, well there's a surprise!
Quote:
Originally Posted by firewall log
01 July 2004 21:02:35 Unrecognized access from 62.253.160.70:65535 to TCP port 2745
01 July 2004 21:02:35 Unrecognized access from 62.253.160.70:65535 to TCP port 3127
01 July 2004 21:02:35 Unrecognized access from 62.253.160.70:65535 to TCP port 420
01 July 2004 21:02:35 Unrecognized access from 62.253.160.70:65535 to TCP port 5000
01 July 2004 21:02:35 Unrecognized access from 62.253.160.70:65535 to TCP port 25
Quote:
Originally Posted by Reverse DNS search
Answer:
62.253.160.70 PTR record: please.see.www.security.scanner.ntli.net
But not much info yet...
www.security.scanner.ntli.net
altis is offline   Reply With Quote
Old 02-07-2004, 00:17   #4
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,247
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: NTL Security probe

Yep - I got scanned tonight - they all bounced off my firewall.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 02-07-2004, 15:16   #5
Shaun
Inactive
 
Join Date: Jun 2003
Posts: 6,064
Shaun has a nice shiny starShaun has a nice shiny star
Shaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny starShaun has a nice shiny star
Re: NTL Security probe

Whats it for? Are they checking how many people have firewalls? Or how many are running servers?
Shaun is offline   Reply With Quote
Old 02-07-2004, 15:24   #6
Mick
Cable Forum Admin
 
Mick's Avatar
 
Join Date: Jun 2003
Posts: 15,139
Mick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny star
Mick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny starMick has a nice shiny star
Re: NTL Security probe

Just checking through my firewall logs, got scanned lastnight, tried to scan port 25 so I can only assume they are checking customers machines to determine if they are operating as a web or mail server.
Mick is offline   Reply With Quote
Old 02-07-2004, 16:56   #7
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,247
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: NTL Security probe

Quote:
Originally Posted by dellwear
Whats it for? Are they checking how many people have firewalls? Or how many are running servers?
Both probably.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 02-07-2004, 20:39   #8
SOSAGES
Inactive
 
SOSAGES's Avatar
 
Join Date: Jan 2004
Posts: 2,379
SOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of societySOSAGES is a pillar of society
Re: NTL Security probe

u wasnt allowed to run webservers originally was u ? i think u can - i checked my logs i cant find any scans on that IP
SOSAGES is offline   Reply With Quote
Old 02-07-2004, 23:06   #9
KraGorn
Inactive
 
Join Date: Nov 2003
Location: Warrington
Posts: 37
KraGorn is an unknown quantity at this point
Re: NTL Security probe

How typical of NTL to lie about what they're doing .. "network maintenance" doesn't need to port scan specific ports like these.
KraGorn is offline   Reply With Quote
Old 03-07-2004, 00:10   #10
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,247
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: NTL Security probe

Quote:
Originally Posted by KraGorn
How typical of NTL to lie about what they're doing .. "network maintenance" doesn't need to port scan specific ports like these.
How exactly are they lying ? - do you have some inside knowledge on what they are scanning for ? - they have told you that you will be scanned, and they were right.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 03-07-2004, 03:41   #11
nopcode
Inactive
 
nopcode's Avatar
 
Join Date: Jan 2004
Location: Scunthorpe
Age: 47
Services: TV M , 10MB BB
Posts: 147
nopcode will become famous soon enoughnopcode will become famous soon enoughnopcode will become famous soon enough
Send a message via MSN to nopcode Send a message via Yahoo to nopcode
Re: NTL Security probe

I have heard from 2 friends on NTL who have had letters about spam emails (supposedly) originating from their NTL email accounts, (even tho they havent been involved in that activity). In both cases ive talked them through removing any malware/trojans, to stop NTL from d/c'ing them as stated in the letter.

Im half sure some new virus/trojan/malware is specifically targeting ntl connections through fake emails and/or ntl network port scans (to find unporotected pc's) .
I myself have had alot of unusual firewall activity, and alot of disconects from the BB service when using online games/messenger apps/web browsing.
Although im at a loss to say who/what is causing the abnormal traffic, i know it is there.

edit! hmm the relation to this this thread was supposed to be, that NTL must be probing/scanning ntl addresses (hopefully not the reason for my D/c's ) , to find out which ones are being exploited by mass mailer daemons, or other malware or maybe even p2p usage. as in the letters to my friends about it.

btw just as i was writing this i got 4 zone alarm blocked msgs. all from same ip but diff ports.
IP:219.150.118.21 on ports 12490,29503,13694.10596 all to my ip on port 1026.

funnily enough this is linked to a dos attack

hmm maybe ET is trying to get noticed
nopcode is offline   Reply With Quote
Old 03-07-2004, 04:31   #12
BBKing
R.I.P.
 
BBKing's Avatar
 
Join Date: Jun 2003
Location: London
Services: 20Mb VM CM, Virgin TV
Posts: 5,983
BBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny star
BBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny starBBKing has a nice shiny star
Send a message via ICQ to BBKing
Re: NTL Security probe

Quote:
How typical of NTL to lie about what they're doing .. "network maintenance" doesn't need to port scan specific ports like these.
Pass the crack pipe, Alice. What does this have to do with network maintenance? I happen to know ntl do rather a lot of network maintenance, I'm involved with it.
BBKing is offline   Reply With Quote
Old 03-07-2004, 09:25   #13
KraGorn
Inactive
 
Join Date: Nov 2003
Location: Warrington
Posts: 37
KraGorn is an unknown quantity at this point
Re: NTL Security probe

Quote:
Originally Posted by BBKing
Pass the crack pipe, Alice. What does this have to do with network maintenance? I happen to know ntl do rather a lot of network maintenance, I'm involved with it.
SO, what DO port scans have to do with network maintenance? More specifically, why THESE ports in particular. Random probes I may accept have use, these are too specific .. they're looking for something and not saying what it is, instead they're inferring it's routine 'maintenance'.

THAT's why they're lying!
KraGorn is offline   Reply With Quote
Old 03-07-2004, 12:28   #14
dev
Inactive
 
Join Date: Jan 2004
Posts: 1,164
dev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond reputedev has a reputation beyond repute
Re: NTL Security probe

Quote:
Originally Posted by KraGorn
SO, what DO port scans have to do with network maintenance? More specifically, why THESE ports in particular. Random probes I may accept have use, these are too specific .. they're looking for something and not saying what it is, instead they're inferring it's routine 'maintenance'.

THAT's why they're lying!
they are most likely looking for viruses/worms spreading by windows exploits or whatever, that is maintenance as it will cut down traffic on the network making more available to you and making the network quicker
dev is offline   Reply With Quote
Old 03-07-2004, 13:48   #15
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,247
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: NTL Security probe

Quote:
Originally Posted by dev
they are most likely looking for viruses/worms spreading by windows exploits or whatever, that is maintenance as it will cut down traffic on the network making more available to you and making the network quicker
Precisely.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 23:56.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum