[Dshield] constant scans from my own ISP

John Groseclose iain at caradoc.org
Sun Aug 5 22:26:06 GMT 2001

At 5:11 PM -0400 8/5/01, Dovescom wrote:
I have been getting scanned constatly from the following segment 
65.92.*.* I am using stars for the last 2 sets as it is all over the 
range given to BellNexus. The sad part is it is my ISP. I called tech 
support and asked if they were infected with the code red worm or if 
it was a script from their servers as it was all over their block, he 
told me " well sir I garentee you it is not our system that is doing 
the scans. If you think you have a valid complaint sumit it to 
<mailto:Abuse at sympatico>Abuse at sympatico I told him I would do so, but 
would also be posting my logs to Dshield,(something I did not want to 
do as it was my own ISP) and he said that was fine. I thaough that by 
calling them it could be resolved relitivly easily but.....

It's that exact attitude from sympatico.ca's "admins" that led me to 
block all e-mail from them to the majority of my accounts.

I got *really* tired of getting nothing but spam from them.

Chances are fairly good that the IPs you have are for co-located 
machines, and Sympatico is simply brushing off any responsibility 
they might have.

Post the logs.
John Groseclose
iain at caradoc.org

More information about the list mailing list