Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Getting "probed" by NTL customers.....

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service

Getting "probed" by NTL customers.....
Reply
 
Thread Tools
Old 10-06-2004, 22:36   #1
Electrolyte01
Guest
 
Posts: n/a
Angry Getting "probed" by NTL customers.....

OK, what is going on? My FTP server which is running black ice defender is reporting people on NTL port scanning me, such as HTTP scans and FTP scans. Some one tried it 36 times, and I'm wanting to know if this is on purpose or they have caught a program that does this.

Any ideas?
  Reply With Quote
Advertisement
Old 10-06-2004, 22:53   #2
quadplay
Inactive
 
Join Date: Jun 2003
Location: Various
Services: 9am, 1pm and 8pm daily
Posts: 2,055
quadplay has a bronze arrayquadplay has a bronze arrayquadplay has a bronze array
quadplay has a bronze arrayquadplay has a bronze arrayquadplay has a bronze arrayquadplay has a bronze arrayquadplay has a bronze arrayquadplay has a bronze arrayquadplay has a bronze array
Re: Getting "probed" by NTL customers.....

Port scans are against ntl's Residential Internet Terms & Conditions. Please report such activity to the Abuse team by visiting www.ntlworld.com/netreport

Thanks!
quadplay is offline   Reply With Quote
Old 10-06-2004, 22:54   #3
Chris W
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: Getting "probed" by NTL customers.....

It could be either... either way report it to the abuse team (www.ntlworld.com/netreport)

the policy on port scanning is three strikes and your out.

EDIT: Jimbo beat me to it...
Chris W is offline   Reply With Quote
Old 10-06-2004, 23:05   #4
Electrolyte01
Guest
 
Posts: n/a
Re: Getting "probed" by NTL customers.....

It asks for evidence, but I can't find a program to open up Black Ice's evidence file. Any ideas of one on the net to show the proof of them both?
  Reply With Quote
Old 10-06-2004, 23:06   #5
Chris W
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: Getting "probed" by NTL customers.....

what form is the output from black ice? there should be a text log file and you can just copy and paste the appropriate part
Chris W is offline   Reply With Quote
Old 10-06-2004, 23:08   #6
Electrolyte01
Guest
 
Posts: n/a
Re: Getting "probed" by NTL customers.....

Black Ice uses .enc because it saves a packet and gives detailed information about it. I think I have found a decoder though

EDIT: This is going to be hard, it's a load of code I don't understand
  Reply With Quote
Old 10-06-2004, 23:22   #7
MetaWraith
Inactive
 
MetaWraith's Avatar
 
Join Date: Oct 2003
Location: 2nd CPU to the right & past the cache
Posts: 1,949
MetaWraith has a bronzed appealMetaWraith has a bronzed appeal
MetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appeal
Send a message via ICQ to MetaWraith Send a message via AIM to MetaWraith Send a message via MSN to MetaWraith Send a message via Yahoo to MetaWraith
Re: Getting "probed" by NTL customers.....

Extract from http://www.iss.net/security_center/a...14/default.htm

The Packet Log and Evidence Log features of BlackICE generate files with the extension ".enc". These ".enc" files contain actual network traffic and in the case of evidence files, they contain traffic that was part of the detected attacks. These files are not readable by normal text editor programs, such as Notepad, but must instead be decoded by standard protocol analyzer programs (sniffers) that network technicians typically use to analyze network traffic.

You can find sniffers (protocol analyzers) to read the packet log and evidence log files at the following web sites: That said, you can read some of the log in texteditors like notepad, but not much of it will make sense, unless some plain text was included in the packet that triggered the capture
MetaWraith is offline   Reply With Quote
Old 10-06-2004, 23:44   #8
Electrolyte01
Guest
 
Posts: n/a
Re: Getting "probed" by NTL customers.....

What part on Ethereal am I supposed to copy and past? I found the IP of the attacker and the port he scanned me (80), but in the middle window I don't know what lines I need to tell NTL about.
  Reply With Quote
Old 11-06-2004, 00:33   #9
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,706
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Getting "probed" by NTL customers.....

All NTL really need are the IP, the port scanned and the time/frequency of the scans. Unless it is persistant then it is probably not worth bothering.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 11-06-2004, 00:51   #10
Chris W
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: Getting "probed" by NTL customers.....

Quote:
Originally Posted by Electrolyte
What part on Ethereal am I supposed to copy and past? I found the IP of the attacker and the port he scanned me (80), but in the middle window I don't know what lines I need to tell NTL about.
might as well copy all information that you think might be relevant... someone working for the abuse team can sort through it

At the time of the Blaster/ Welchia worms i was sending 150+ pages of router logs everyday to one of the teams at work so they could get all of the ips. Needless to say they did a pretty good job of sorting through them
Chris W is offline   Reply With Quote
Old 11-06-2004, 05:43   #11
deadite66
Inactive
 
deadite66's Avatar
 
Join Date: Jun 2003
Location: great yarmouth
Services: Zen Fibre, Asus RT-AC68U
Posts: 900
deadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these parts
Re: Getting "probed" by NTL customers.....

install http://www.mynetwatchman.com/ and let them automaticaly send reports to the isp for you.

like this naughty ntlworld user. http://www.mynetwatchman.com/LID.asp?IID=101544654
deadite66 is offline   Reply With Quote
Old 11-06-2004, 07:10   #12
Electrolyte01
Guest
 
Posts: n/a
Angry Re: Getting "probed" by NTL customers.....

Thanks for that program, i'm installing it right away because I am being attacked from loads of people
  Reply With Quote
Old 11-06-2004, 08:52   #13
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: Getting "probed" by NTL customers.....

I use this. http://www.visualizesoftware.com/for Zone Alarm, they do a version for Black Ice, not free but produces loads of extra info on your firewall activity and can generate email messages from within the program that you can send to abuse@ anywhere.
iadom is offline   Reply With Quote
Old 11-06-2004, 09:10   #14
Electrolyte01
Guest
 
Posts: n/a
Re: Getting "probed" by NTL customers.....

I installed mynetwatchman, and it sent off all the "possible" attacks I had in my Black Ice attack list. At least it's automatic
  Reply With Quote
Old 11-06-2004, 09:57   #15
poolking
Inactive
 
Join Date: Jun 2003
Location: Stafford
Age: 52
Services: Sky World 300k BB NTL Phone
Posts: 2,399
poolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant futurepoolking has a brilliant future
Send a message via AIM to poolking Send a message via MSN to poolking Send a message via Yahoo to poolking
Re: Getting "probed" by NTL customers.....

Are you positive they are "attacks" it could just be normal internet traffic?
poolking is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 15:26.


Server: lithium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum