Discussion:
81.106.210.146
(too old to reply)
Mike Scott
2005-03-11 12:08:53 UTC
Permalink
Anyone else having 81.106.210.146 (oxford) regularly in their firewall
logs? It's been poking at a range of ports here since at least late
Jan, which is when my security logs date back to.

I logged a complaint via the ntl web site a few days ago, but still the
probes continue..... not that I'm surprised.
--
Please use the corrected version of the address below for replies.
Replies to the header address will be junked, as will mail from
various domains listed at www.scottsonline.org.uk
regards. Mike Scott Harlow Essex England.(unet -a-t- scottsonline.org.uk)
James Hodson
2005-03-11 15:27:43 UTC
Permalink
On Fri, 11 Mar 2005 12:08:53 GMT, Mike Scott
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their firewall
logs? It's been poking at a range of ports here since at least late
Jan, which is when my security logs date back to.
Hi Mike

I had a few instances of 81.106 (not 81.106.210.146) between Sept and
Dec last year.

James
Mark McIntyre
2005-03-11 15:50:19 UTC
Permalink
On Fri, 11 Mar 2005 12:08:53 GMT, Mike Scott
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their firewall
logs? It's been poking at a range of ports here since at least late
Jan, which is when my security logs date back to.
Its a zombie PC & happens all the time. No point worrying about it,
just leave your f/w blocking it and if you can be a**ed, report it to
ntl.
Post by Mike Scott
I logged a complaint via the ntl web site a few days ago, but still the
probes continue..... not that I'm surprised.
ntl don't seem to act on reports unless they get a heck of a lot per
IP. Shame really, its good PR to do something and its trivial to do
it.
David Norris
2005-03-11 16:49:50 UTC
Permalink
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their firewall
logs? It's been poking at a range of ports here since at least late
Jan, which is when my security logs date back to.
I logged a complaint via the ntl web site a few days ago, but still the
probes continue..... not that I'm surprised.
I get a lot of probes from a machine on my subnet on the linuxconf port.
Some services such as, I belive PC anywhere automatically look to see any
other instances of themselves running nearby.

DN
©¿©¬ Pendragon
2005-03-12 11:51:42 UTC
Permalink
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their firewall
logs? It's been poking at a range of ports here since at least late
Jan, which is when my security logs date back to.
I logged a complaint via the ntl web site a few days ago, but still the
probes continue..... not that I'm surprised.
I sure posting the IP in a public forum will ensure he gets some
attention...

Not NTL of course, it would be too much to expect any commercial
orginisation to respond to something that doesn't affect their bottom
line directly.
--
©¿©¬
Regards Steve Morrish...
AKA: (]TSS[)PENDRAGON
ICQ: 112044096
Chet
2005-03-12 12:36:22 UTC
Permalink
Post by ©¿©¬ Pendragon
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their firewall
logs? It's been poking at a range of ports here since at least late
Jan, which is when my security logs date back to.
I logged a complaint via the ntl web site a few days ago, but still the
probes continue..... not that I'm surprised.
I sure posting the IP in a public forum will ensure he gets some
attention...
Not NTL of course, it would be too much to expect any commercial
orginisation to respond to something that doesn't affect their bottom
line directly.
This is why you have a firewall is it not, how can you expect NTL to chase
every IP address the enters your firewall log, most of the time the IP that
ends up in your log is not the originating IP address anyway, and if its
your log it has been stopped so stop worrying about it

@ Pendraqgon, you are leaving yourself wide open for spam if you leave your
mail address open for all to see
©¿©¬ Pendragon
2005-03-12 14:09:53 UTC
Permalink
Chet wrote:
<SNIP>
Post by Chet
@ Pendraqgon, you are leaving yourself wide open for spam if you leave your
mail address open for all to see
The email address is left open deliberately, I'm running a little test.

Is the NTL spam filter any good??

So far so good, only about 1 every couple of weeks. I would like to get
back to the "good old days" before spam!! when you could email a reply
to a post instead of everything havening to posted back to the group.
--
©¿©¬
Regards Steve Morrish...
AKA: (]TSS[)PENDRAGON
ICQ: 112044096
Chris Jones
2005-03-12 20:43:31 UTC
Permalink
Post by ©¿©¬ Pendragon
Is the NTL spam filter any good??
No, but its better than nothing
Andrew Chesters
2005-03-12 21:40:04 UTC
Permalink
Post by Chris Jones
Post by ©¿©¬ Pendragon
Is the NTL spam filter any good??
No, but its better than nothing
From my limited experience, nothing is precisely what they use.
Hyracotherium
2005-04-16 17:17:50 UTC
Permalink
Post by ©¿©¬ Pendragon
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their
firewall logs? It's been poking at a range of ports here since at
least late Jan, which is when my security logs date back to.
I logged a complaint via the ntl web site a few days ago, but still
the probes continue..... not that I'm surprised.
I sure posting the IP in a public forum will ensure he gets some
attention...
Not NTL of course, it would be too much to expect any commercial
orginisation to respond to something that doesn't affect their bottom
line directly.
Try http://www.mynetwatchman.com/LID.asp?IID=147349291
or
http://www.dshield.org/ipinfo.php?ip=81.106.210.146&Submit=Submit
--
Rgds Tony
Mike Scott
2005-04-18 09:28:47 UTC
Permalink
Post by Hyracotherium
Post by Mike Scott
Anyone else having 81.106.210.146 (oxford) regularly in their
firewall logs? It's been poking at a range of ports here since at
least late Jan, which is when my security logs date back to.
...
Post by Hyracotherium
Try http://www.mynetwatchman.com/LID.asp?IID=147349291
or
http://www.dshield.org/ipinfo.php?ip=81.106.210.146&Submit=Submit
Ta muchly. Checking the logs, it seems they stopped on 12th March - no
entries since then.
--
Please use the corrected version of the address below for replies.
Replies to the header address will be junked, as will mail from
various domains listed at www.scottsonline.org.uk
Mike Scott Harlow Essex England.(unet -a-t- scottsonline.org.uk)
Loading...