I guess I must have a *special* ISP then, too.  Or else, I have a good
relationship with mine.  I have no problems getting them to act on
portscanning/Nimda-scanning activities - in fact, normally by the time I
report what the tarpit sees, they have taken the machine off the 'Net and
told the person to fix it.  Of course, the fact that the original Code Red
attack wreaked havoc with their DSL customers, who mostly had Cisco 67x
routers (which locked up when it with CR probes) may have helped.  But, I
think it is mostly due to the fact that they are a small ISP/consulting
firm, who needs an edge to stay competitive - and that edge, for them, is

> "Port scanning wastes bandwidth, bandwidth that ISPs have to purchase"
> The bandwidth used by port scanning or for that matter all ICMP traffic is
> small potatoes. One user streaming videos, or downloading big warez apps
> a bigger issue.
> You must have a special ISP, most won't act on port-scanning complaints.
> Like ICMP echo, it is just knocking on doors looking for a response. Most
> AUP's specify PC security is the users responsibility. As far as working
> with other ISPs to report and prevent port scanning...there are more fun
> ways to waste time. You can lodge a complaint to the abuse address or the
> ARIN listed contact, but don't hold your breath waiting on a response.
> -Ian

