Jump to content

Recommended Posts

Posted

I'm currently fuming with Tiscali/TalkTalk. I have an IP attempting to intrude into my network (56-640k traffic to port 443 of my mail server every 2 seconds since tuesday) I have set firewall to drop packets already but Tiscali have just told me that "it is against there policy to intrude onto what there customers are doing online" and when I told him that this wasn't a good enough answer and that I wanted to speak to his supervisor he hung up.

 

I've emailed the abuse address, is there anything more I can do?

 

I'm sure his repsonse was a 'we can't bothered to do anything' not 'we can't do anything' as I've previously been phoned by three different ISPs to tell me that something on my network is awry. First on my home network (BT) for my sisters dev server which she accidentally left as an open relay, once on a network I was looking (demon) after to tell me one of my clients was compromised and sending out a similar level of requests, and once recently (SWGFL) to tell me that traffic was arriving at there network from a route which wasn't their router and they didn't like it much. So I know it's possible. what is their problem?

Posted

They are obliged to do something of course - naturally they won't give out any details for obvious reasons but they do have to look into it. Anything further than that (i.e. getting back to you saying they've taken action) is optional. It would of course be nice to know even if they get back to you and say it's a customer's machine that's been compromised or something and they've taken steps to help that customer.

 

Unfortunately other than being unprofessional, ignorance is rather common with many ISPs, and we all know what Talktalk are like. Big companies (Hetzner is a good recent example) have had half their entire traffic cut in the past because they couldn't be arsed to act on things like this.

  • Thanks 1
Posted

I'm assuming the guy you spoke to was a first-line scriptreader? abuse@ is the appropriate contact for reporting technical things. Their helldesk will be largely geared towards "reboot your router" type problems and will mostly segfault on anything outside the script.

 

You could always try Richard Lawrence if you don't get anywhere: Richard Lawrence - United Kingdom | LinkedIn

  • Thanks 1
Posted

I think having a policy of not blocking things without a court order is a good thing.

Imagine the hassle they'd have with maintaining all the firewall rules if every customer was asking for things to be blocked at the ISP level.

  • Thanks 1
Posted
I'm not asking them to block something, i'm asking them to check the quantity of traffic from one user and contact them to perhaps suggest they may have a virus of some sort.
Posted
I'm assuming the guy you spoke to was a first-line scriptreader? abuse@ is the appropriate contact for reporting technical things. Their helldesk will be largely geared towards "reboot your router" type problems and will mostly segfault on anything outside the script.

 

You could always try Richard Lawrence if you don't get anywhere: Richard Lawrence - United Kingdom | LinkedIn

 

I'm not sure. The first person I spoke to was called Aled and took down my name and organisation, the attacking IP, my IP my contact etc. I then got put on hold while went to get advice as to who to put me through to, I was on hold for about 5 minutes and when I got picked up again it was an indian guy who wouldn't really listen.

Posted
I'm not asking them to block something, i'm asking them to check the quantity of traffic from one user and contact them to perhaps suggest they may have a virus of some sort.

 

oh I see. Can you get any info from the IP to contact them yourself?

  • Thanks 1
Posted
oh I see. Can you get any info from the IP to contact them yourself?

 

the IP resolves to a dynamic pool from tiscali and suggests either central london or windsor. the last hop on a traceroute before it times out is 85.210.255.137 which suggests it is in hounslow. more than that I can't gather, unless there is a tool i'm missing...

Posted
oh I see. Can you get any info from the IP to contact them yourself?

All you can get from an IP is the owner of the block; which will be the ISP.

Without a court order, you wont be able to match the specific IP to a customer.

Due to the huge level of 'background static' of compromised machines launching attacks against services and scanning ports no ISP is going to chase up and block intrusion attempts unless it is affecting any Service Level agreements they have with the affected customer.

Really the only options open is to report it via abuse@ to the ISP of the originating traffic and your own ISP. Configure your edge firewall to drop packets from those addresses and monitor your service levels. If it has too much effect on your available bandwidth then you can complain to your ISP

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...