Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Merged - Port blocking

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Merged - Port blocking
Reply
 
Thread Tools
Old 16-12-2003, 16:11   #31
Fawkes
Inactive
 
Fawkes's Avatar
 
Join Date: Oct 2003
Location: Manchester
Age: 49
Services: VM: 120M Broadband, TV + Landline
Posts: 471
Fawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond reputeFawkes has a reputation beyond repute
Re: Port blocking

Quote:
Originally Posted by zovat
Just a point - according to the port block list on NTLs website - port 135 is NOT being blocked -




Am I misreading this or is this the case ?
Your misreading:

Quote:
Following last month's decision to block 'port 135', ntl:home is blocking more Internet ports to reduce the threat of the new virulent worms that may use these ports to spread across the Internet.

This "port-blocking" should have little or no effect on your use of the Internet but it will significantly reduce the vulnerability to infection from variants of the Welchia and MSBlast worms.

The ports being blocked (inbound only, to stop infections) are: 137 (UDP), 138 (UDP), 139 (TCP), 445 (UDP & TCP), 593 (TCP), 1433 (TCP), 1434 (UDP), 27374 (TCP)
Taken from here.
Fawkes is offline   Reply With Quote
Advertisement
Old 16-12-2003, 16:11   #32
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: Port blocking

Quote:
Originally Posted by zovat
Just a point - according to the port block list on NTLs website - port 135 is NOT being blocked -




Am I misreading this or is this the case ?
According to this thread and also from recent experience, this was the first port that Ntl blocked followed soon after by the ones in the list. I think that page on the Ntl website is a list of the other ports they decided to block as well.
As I mentioned I have had absolutely no 135 scans since they started blocking until this morning, now they are flooding in just as before blocking.

http://forum.nthellworld.co.uk/showt...light=Port+135

EDIT, Thanks Fawkes, was just about to post that link but you saved me the trouble. I just find it weird that no one else in the N/West has reported anything similar yet, but the night is young.
As you can see from attached jpeg, I am also getting 139 & 445 scans as well, even though these are supposed to be blocked.
iadom is offline   Reply With Quote
Old 16-12-2003, 16:28   #33
zovat
Inactive
 
zovat's Avatar
 
Join Date: Oct 2003
Location: Bracknell
Age: 56
Services: NTL Telephone 3M Broadband - CM Sky TV
Posts: 1,246
zovat has reached the bronze age
zovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze age
Send a message via MSN to zovat
Re: Port blocking

Quote:
Originally Posted by Fawkes
Your misreading:



Taken from here.

cheers for that - I missed the first bit - sorry
zovat is offline   Reply With Quote
Old 16-12-2003, 18:54   #34
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,565
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Port blocking

I can confirm that nothing is getting to me on port 135.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 16-12-2003, 21:15   #35
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: Port blocking

I'm not surprised, they are all attacking me. Over 600 hits in the past 5 hours, ports 135/139/445 mainly, and these are supposed to be blocked.

I am going to shut down now and see what tomorrow brings.
iadom is offline   Reply With Quote
Old 16-12-2003, 21:25   #36
utt
Inactive
 
Join Date: Dec 2003
Posts: 98
utt is an unknown quantity at this point
Re: Port blocking

Quote:
Originally Posted by iadom
I'm not surprised, they are all attacking me. Over 600 hits in the past 5 hours, ports 135/139/445 mainly, and these are supposed to be blocked.

I am going to shut down now and see what tomorrow brings.

iadom...
Please check with Neil who I am, and then please pm me your details, we would like to investigate why you are getting these hits on your firewall.

Thanks
UTT
utt is offline   Reply With Quote
Old 17-12-2003, 06:45   #37
Stuartbe
Inactive
 
Join Date: Jan 2023
Posts: 4,984
Stuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this point
Stuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this point
Angry Are Isp's Right To Block Mail From Dynamic IP's ??

Hi All.

I know that you are not suposed to run your own mail servers on a broadband connection with NTL but many people do. I do as I simply can not rely on NTL'S poor mail servers (when they are actualy up that is ! )

I am now finding that a large number of mail servers are rejecting mail from dynamic ip's that are sent directly. I can understand why they are doing this as there must be a huge number or servers that are completely insecure or set up as open relays. This is purely down to ignorant people that simply slap on a mail server package with no knowlege of how to secure it. These users should have there cable modems inserted where the sun doesn't shine as they are giving people that do run proper mail servers a bad rep. There sulution to this is to use the NTL smtp as a smart host !!!!!! :-( NOT GOOD !!!

There are users out there that do know what they are doing and dont pose a risk as open relays or spam portals. If you are a small company like we are a leased line is out of the question.

Looks like the average home or small company has no choice but to rely on there ISP'S mail servers even though they are often unstable and usualy a bigger relay of spam than most home servers.

Does any one know if NTL have multiple mail servers in diferent parts of the U.K. or do they just have the one ?
Stuartbe is offline   Reply With Quote
Old 17-12-2003, 08:17   #38
darkangel
Inactive
 
darkangel's Avatar
 
Join Date: Jun 2003
Location: manchester
Age: 85
Posts: 553
darkangel is a jewel in the roughdarkangel is a jewel in the roughdarkangel is a jewel in the roughdarkangel is a jewel in the roughdarkangel is a jewel in the rough
Re: Are Isp's Right To Block Mail From Dynamic IP's ??

Quote:
Originally Posted by stuartbe
Hi All.

I know that you are not suposed to run your own mail servers on a broadband connection with NTL but many people do. I do as I simply can not rely on NTL'S poor mail servers (when they are actualy up that is ! )

I am now finding that a large number of mail servers are rejecting mail from dynamic ip's that are sent directly. I can understand why they are doing this as there must be a huge number or servers that are completely insecure or set up as open relays. This is purely down to ignorant people that simply slap on a mail server package with no knowlege of how to secure it. These users should have there cable modems inserted where the sun doesn't shine as they are giving people that do run proper mail servers a bad rep. There sulution to this is to use the NTL smtp as a smart host !!!!!! :-( NOT GOOD !!!

There are users out there that do know what they are doing and dont pose a risk as open relays or spam portals. If you are a small company like we are a leased line is out of the question.

Looks like the average home or small company has no choice but to rely on there ISP'S mail servers even though they are often unstable and usualy a bigger relay of spam than most home servers.

Does any one know if NTL have multiple mail servers in diferent parts of the U.K. or do they just have the one ?
never had any problems with ntl's e-mail but are u saying that u are using the residential service for your business? surely there are plenty of private e-mail providers that will give u guaranteed service
darkangel is offline   Reply With Quote
Old 17-12-2003, 08:40   #39
Stuartbe
Inactive
 
Join Date: Jan 2023
Posts: 4,984
Stuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this point
Stuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this pointStuartbe is an unknown quantity at this point
Re: Are Isp's Right To Block Mail From Dynamic IP's ??

Im self employed so a business connection is simply out of my budget. I need web mail access to the server and I also need to send digitaly sig. mail out.
Stuartbe is offline   Reply With Quote
Old 17-12-2003, 08:46   #40
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: Port blocking

Will do ,thanks for that. Have just booted up and the firewall was hit within seconds.

jim.
iadom is offline   Reply With Quote
Old 17-12-2003, 08:53   #41
th'engineer
Inactive
 
th'engineer's Avatar
 
Join Date: Jun 2003
Location: Middleton North West Manchester
Services: up to 30 MEG CF version of Peter Kay
Posts: 1,871
th'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to all
Send a message via MSN to th'engineer
Re: Port blocking

Quote:
Originally Posted by iadom
Will do ,thanks for that. Have just booted up and the firewall was hit within seconds.

jim.
Jim get that router you promised yourself for xmas it will stop them
th'engineer is offline   Reply With Quote
Old 17-12-2003, 08:58   #42
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: Port blocking

Quote:
Originally Posted by th'engineer
Jim get that router you promised yourself for xmas it will stop them
Thanks Steve, I should have put a request in the Christmas presents thread.
Strange why I have just suddenly started to get these,

PS, my memory is a bit vague this morning, I was out on my first call at 7.30 and it was b***** cold. How do I obtain my MAC address.

EDIT: Cancel that ,good old Robin Walker pages, I knew I had seen MAC info somewhere.
iadom is offline   Reply With Quote
Old 17-12-2003, 09:07   #43
cliveb
Inactive
 
Join Date: Nov 2003
Location: Watford
Posts: 30
cliveb is an unknown quantity at this point
Re: Are Isp's Right To Block Mail From Dynamic IP's ??

Quote:
Originally Posted by stuartbe
There are users out there that do know what they are doing and dont pose a risk as open relays or spam portals. If you are a small company like we are a leased line is out of the question.
There is a very good reason why mail sent direct from a dynamic IP can't be trusted. Although at the moment, that dynamic IP happens to belong to you, and you can be trusted, tomorrow that IP might be handed out to someone else who is running an open relay. (I know IP addresses in NTL tend to stick around, but they *can* change - mine did a couple of weeks ago after a hardware "upgrade" at NTL's end).

I agree with you that NTL's SMTP servers can't be trusted (nor can their POP3 servers for that matter), so the only real solution is to buy email services from a reliable third party. I happen to use UK Web Solutions Direct, who have been very reliable (20 quid a year for POP3, SMTP, webmail, and 100MB of web space), but I'm sure there are plenty of other suitable providers.
cliveb is offline   Reply With Quote
Old 17-12-2003, 09:42   #44
th'engineer
Inactive
 
th'engineer's Avatar
 
Join Date: Jun 2003
Location: Middleton North West Manchester
Services: up to 30 MEG CF version of Peter Kay
Posts: 1,871
th'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to allth'engineer is a name known to all
Send a message via MSN to th'engineer
Re: Port blocking

Quote:
Originally Posted by iadom
Thanks Steve, I should have put a request in the Christmas presents thread.
Strange why I have just suddenly started to get these,

PS, my memory is a bit vague this morning, I was out on my first call at 7.30 and it was b***** cold. How do I obtain my MAC address.

EDIT: Cancel that ,good old Robin Walker pages, I knew I had seen MAC info somewhere.
IPconfig/all or winipcfg from run dependant on OS
th'engineer is offline   Reply With Quote
Old 17-12-2003, 15:46   #45
iadom
In the corner, sulking.
 
iadom's Avatar
 
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
iadom has a nice shiny stariadom has a nice shiny star
iadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny stariadom has a nice shiny star
Re: Merged - Port blocking

For attention of utt.


Here is the screen grab you requested from first bootup this morning. Still flooding in, over 400 today up to now.

Jim.
iadom is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:17.


Server: lithium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum