Check your service statusCable National
Searching for something?
Reply
Expert Opinionator
Champs
Posts: 1,351
Registered: ‎30-10-2010

Re: Port Scanning Abuse

If you have blocked it and its not causing a problem then what is all the concern about?

 

Google that ip address quite a few people from all different isp's have had it, some dateing back in 2009. Just ignore it

______________________________________________________________
**I am employed by Virgin Media**
**Everything I post is in my own time and my own opinion**
Please use plain text.
Crafty
TuftyDave
Posts: 25
Registered: ‎02-12-2010

Re: Port Scanning Abuse

[ Edited ]

Here's some of todays:

Fri, 2010-12-17 17:55:24 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,9415 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:24 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,3246 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:25 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,1080 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:25 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:25 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:25 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:26 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Fri, 2010-12-17 17:55:26 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,7212 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,1080 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8118 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Fri, 2010-12-17 18:32:36 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3246 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8118 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,7212 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200

Destination:**.**.***.**,73 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200

Destination:**.**.***.**,80 - [Any(ALL) rule match]

Fri, 2010-12-17 21:06:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8080 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:51 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,27977 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:52 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,9415 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:52 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2479 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:52 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,9000 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:53 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:53 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:53 - TCP Packet - Source:58.218.204.110,12200

Destination:**.**.***.**,73 - [Any(ALL) rule match]

Fri, 2010-12-17 22:00:54 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8080 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8085 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,2479 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9000 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200

Destination:**.**.***.**,73 - [Any(ALL) rule match]

Fri, 2010-12-17 23:41:29 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 01:11:24 - Administrator login successful - IP:192.168.0.102

Sat, 2010-12-18 02:04:35 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8085 - [Any(ALL) rule match]

Sat, 2010-12-18 02:04:36 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,9090 - [Any(ALL) rule match]

Sat, 2010-12-18 02:04:36 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,1080 - [Any(ALL) rule match]

Sat, 2010-12-18 02:04:37 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Sat, 2010-12-18 02:04:37 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Sat, 2010-12-18 02:04:38 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,7212 - [Any(ALL) rule match]

Sat, 2010-12-18 02:04:38 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8080 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:51 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9415 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:51 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3246 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:51 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9090 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:51 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8090 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:51 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:52 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 02:16:52 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8080 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9000 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9090 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8090 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,1080 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Sat, 2010-12-18 04:52:44 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:09 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,27977 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:09 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2479 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:09 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,3246 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:09 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,9000 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:10 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8090 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:10 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:10 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:10 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:10 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8118 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:11 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 06:09:11 - TCP Packet - Source:58.218.204.110,12200

Destination:**.**.***.**,80 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8085 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,2479 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,27977 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8090 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,1080 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8118 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,7212 - [Any(ALL) rule match]

Sat, 2010-12-18 09:26:26 - TCP Packet - Source:58.218.199.147,12200

Destination:**.**.***.**,73 - [Any(ALL) rule match]

Sat, 2010-12-18 10:13:29 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2479 - [Any(ALL) rule match]

Sat, 2010-12-18 10:13:29 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,3246 - [Any(ALL) rule match]

Sat, 2010-12-18 10:13:30 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Sat, 2010-12-18 10:13:30 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8118 - [Any(ALL) rule match]

Sat, 2010-12-18 10:13:31 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 10:13:31 - TCP Packet - Source:58.218.204.110,12200

Destination:**.**.***.**,80 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9090 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,27977 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8090 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,1080 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,3128 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8118 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8088 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,7212 - [Any(ALL) rule match]

Sat, 2010-12-18 12:20:47 - TCP Packet - Source:58.218.199.147,12200

Destination:**.**.***.**,73 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:03 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,27977 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:03 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2479 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:04 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,9000 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:04 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:05 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,2301 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:05 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:05 - TCP Packet - Source:58.218.204.110,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 14:18:06 - TCP Packet - Source:58.218.204.110,12200

Destination:**.**.***.**,80 - [Any(ALL) rule match]

Sat, 2010-12-18 14:57:41 - Send out NTP request to 81.168.77.149

Sat, 2010-12-18 14:59:01 - Send out NTP request to time-g.netgear.com

Sat, 2010-12-18 14:59:00 - Receive NTP Reply from time-g.netgear.com

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9415 - [Any(ALL) rule match]

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,9000 - [Any(ALL) rule match]

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8000 - [Any(ALL) rule match]

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,8008 - [Any(ALL) rule match]

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,7212 - [Any(ALL) rule match]

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200 Destination:**.**.***.**,6588 - [Any(ALL) rule match]

Sat, 2010-12-18 15:16:07 - TCP Packet - Source:58.218.199.147,12200

Destination:**.**.***.**,80 - [Any(ALL) rule match]

 

 

EDIT: Removed personal information

Please use plain text.
Crafty
TuftyDave
Posts: 25
Registered: ‎02-12-2010

Re: Port Scanning Abuse

I don't quite understand where you are coming from...

If there were a gang roaming your streets with lock picks attempting to break into every house & people report it who are lucky enough to have good enough locks to stop them getting in, you wouldn't tell the people reporting it to ignore them?

Or maybe you would!

It's the principle of it.

 

They (or their software) are attempting to hack all virgin ip addresses... some of them they will succeed on and cause people great distress.

 

Surely you have the power to contact their ISP and warn them to stop and if they don't block their traffic from ever getting into virgin servers.

 

I reverse your question and ask you "why would you continue to allow it to happen? Why would you NOT stop them?"

 

Not only that, there is already vast ammounts of traffic on the internet, this scanning abuse is just helping waste bandwidth and slow down the whole service.

 

 

Please use plain text.
Expert Opinionator
Champs
Posts: 1,351
Registered: ‎30-10-2010

Re: Port Scanning Abuse

Where do you get the idea there attempting to hack all Virgin ip address's? I have not had this scan me. Also how do you know if it is malicous? its a scan, like google map car driving about mapping stuff collecting info its not doing anything bad. Surely if people have been reporting this since 2009 over different isp's and its still going it cant be anything to bad as something would have been done about it. If it targeted EVERY Virgin internet user and bought utter chaos to users im sure Virgin would be obligated to step in and do something. You are the only person who has reported this, and have done something to protect yourself. Have fun and continue to post logs, just think its a waste of your time.

 

Im sure Virgin should block every scam website, spyware, virus, etc etc its just not possible. Especially when its not actually causing a problem

______________________________________________________________
**I am employed by Virgin Media**
**Everything I post is in my own time and my own opinion**
Please use plain text.
Crafty
TuftyDave
Posts: 25
Registered: ‎02-12-2010

Re: Port Scanning Abuse

The reason I know it's every port, is that I've deliberately switched off my modem on various occasions to deliberately DROP my allocated IP address. I then switch it bak on & am given a NEW IP address.... within an hour or so that NEW IP addressis being port scanned again by this same Chinese ISP.

 

The reason I know it's not just 'usual' traffic is I took some time before bothering you with it, to check that it wasn't.

Aparently if it were 'usual' traffic you now & again see programs scanning ports using various ports at their end and your end. This is always only one port at their end, namely 12200 and to quote one web site "The port 12200 has been associated with scanners looking for open proxies to take over maliciously"

Other security sites also warn you to look out for exactly this type of port scanning.

 

I didn't just swamp you with logs for no reason!

 

I firstly attempted 3 times to contact the Chinese ISP which resulted in their blocking my email address without even acknowledging my emails!

 

If it were a harmless 'usual' use of port scanning, do you not think they would have just explained that to me?

 

If you look there ARE reports of lots of Virgin users being scanned by this Chinese ISP

Not everyone will have modern routers that block port scans, so it's quite likely that they ARE managing to hack into some peoples PC's. Otherwise they wouldn't keep doing it for so long!

But there's no incentive for them to stop is there, since no one is going to even attempt to stop them.

 

The thing is, I understand what you're saying & I know that there is port scanning going on all the time for valid reasons. But for example there is a site "epillion.com" "internet detective" who have had hundreds of complaints about this Chinese ISP:

"We have 132 complaints about 58.218.204.110
We have 115 complaints about 58.218.199.147"

but I really don't know what - if anything - they actually DO about the reports they get apart from list them for others to see!

 

So it seems this Chinese ISP IS allowing bots to run malicious software to port scan IP addresses, but just like you,  most people are saying "Oh it happens all the time, most people are protected, so it's OK"

 

If that's the case then there's really nothing any of us can do.

 

I just feel really sorry for the people who are unlucky enough to get hacked by these !£%$"'s simply because no one is prepared to even FIND OUT why they are doing what they are doing & stop them if it isn't totally above board.

 

 

 

 

 

 

Please use plain text.
Crafty
TuftyDave
Posts: 25
Registered: ‎02-12-2010

Re: Port Scanning Abuse

Ahh, just done more searching and seeing so many people are getting so **bleep** off that some are starting to blacklist this ISP.

 

So at least someone is taking it seriously and doing something about it.

 

As you say it's pointless me pasting logs here. I'll stop

 

Please use plain text.
Expert Opinionator
Champs
Posts: 1,351
Registered: ‎30-10-2010

Re: Port Scanning Abuse

If you turn off your modem for a while and then are assigned a new ip and within a while it starts scanning your computer again I would be concerned about something on your computer.

 

I have never had this place scan me, and asking a few friends on various ISP's neither have they.

 

Yes I can see some people have had trouble but that is about 0.001% of Virgin Media internet users.

______________________________________________________________
**I am employed by Virgin Media**
**Everything I post is in my own time and my own opinion**
Please use plain text.
Making Waves
AARONLUVSYABABY
Posts: 9
Registered: ‎12-01-2011

Re: Port Scanning Abuse

well whoever this guy is on virgin media doing a level let me tell you straight up that this port scanning is very real......ip 58.218.204.110 is port scanning me also with another ip addy from china...

 

I play online games such as fulltilt poker /absolute poker ,and a host of other gaming sites and these dos attacks keep coming whenever im logged onto thier servers.....

 

they may sound like they are bing blocked packets here but i suspect the DHCP is being overidden and also say as much as they change format codes in the software data pile strings and also please note somehow my virgin media definitions automatically change or upgrade.....really wierd on so many levels .

 

I have tracked the ip usage to china :and one guy in particular named by KONG LINGFEI.....

 

these have been ghosting on my network now for over 2 years and have port scannned every day , I have reported the attacks to both the police who do nothing and the ICC in the usa whom apparently dont even answer emails or give clues as to what is going on......there was a report made on the bbc and one guy in question actually went to china to source the problems out but I have no further info.

 

the packets seem to contain malicious trojans such as winhole, net ministrator and remote access tools.

 

are virgin media going to step up to the plate and admit ip spoofing is what is going on and out data is being manipulated over secure servers?? I mean what the fing hell port scanning is illegal after all and its against terms and conditions to put up with the level of abuse I have suffered enough on there to know.

 

Or do they sit idle by and wait for microsoft to come up with a solution,.....to say it hasnt affected many vm customers i feel outraged because noone even knows its going on **bleep**....too many limp twits out there to realise what the network is even doing most just thinkk yep im connected thatll do etc etc......

 

I spoke to arin ,and also other important data centres such as tata communications in montreal yet Ive had no specific answers as to why I am being port scanned like this......

 

58.218.204.110 please get this ip wiped off the fing planet for good virgin media.

 

 

 

 

 

 

 

 

 

 

 

Please use plain text.
Making Waves
AARONLUVSYABABY
Posts: 9
Registered: ‎12-01-2011

Re: Port Scanning Abuse

lets also keep things in perspective here , You have a physical ip network address then you get a dynamic one also~??

 

surely only need here is to have a proper firewalled dynamic ip and not a static one ,.....

 

or maybe its possible for virgin media customers to opt in and get another service added like a proxy server or have the ip address hidden from public view so that it is 100% safe ..........

 

virgin medai worker above please also note that whilst you think these blocked packets dont harm your computer Im damm sure they do ,u ever hear of flooding ip connection??

 

the problem is they keep flooding the network and thus the data I think that should be coming in is probably somewhat distorted from the real data ....Im not expert but im not stupid either,..........

 

maybe if the virgin media inspected the network packets via deep packet inspection surely they would find out what these chinese network packets are and the information contained within them so that would give me a better idea of the problems im having....

 

 

 

 

 

Please use plain text.
Human Answer Bank
James_G
Posts: 3,890
Registered: ‎16-06-2010

Re: Port Scanning Abuse

Hi all,

 

The best way to resolve this is to contact the ISP the port scan is comming from and provide them with the details. This way they will be able to stop this from happening.

Regards,

James Gilbert

Help & Support Forum Team


If someone's helped you out say thanks by clicking on the Kudos Star. If someone's solved your problem, why not mark their message as an Accepted Solution? You can also help other users find useful posts by Tagging them with keywords.

If you are new to the forum, please remember to search the forum before posting your question.

Please can we ask you not to PM the Forum team unless requested to do so by us
Please use plain text.