Solved

Port scanning - any way to contact the provider?

Posted on 2008-10-08
3
238 Views
Last Modified: 2013-12-14
We're getting thousands of port scannings from
GB/United Kingdom/mobile-032-148-149-213.mycingular.net
where the MAC address is always the same, but the IP address changes (but always mycingular.net)

any suggestions?
0
Comment
Question by:willsherwood
3 Comments
 
LVL 5

Accepted Solution

by:
belowzerotech earned 250 total points
ID: 22670386
you can always do a WHOIS on the IP. this is what I get.

OrgName:    AT&T Global Network Services
OrgID:      ATGS
Address:    3200 Lake Emma Road
City:       Lake Mary
StateProv:  FL
PostalCode: 32746
Country:    US

NetRange:   32.0.0.0 - 32.255.255.255
CIDR:       32.0.0.0/8
NetName:    ATT-32-0-0-0-A
NetHandle:  NET-32-0-0-0-1
Parent:
NetType:    Direct Allocation
NameServer: NS.UK.PRSERV.NET
NameServer: NS.DE.PRSERV.NET
NameServer: NS.NL.PRSERV.NET
Comment:
RegDate:
Updated:    2007-05-22

RTechHandle: IAA17-ARIN
RTechName:   IP Address Administration
RTechPhone:  +1-732-420-2071
RTechEmail:  addrmgt@qsun.att.com

OrgAbuseHandle: ATTAB-ARIN
OrgAbuseName:   ATT Abuse
OrgAbusePhone:  +1-919-319-8130
OrgAbuseEmail:  abuse@att.net

OrgTechHandle: ICC-ARIN
OrgTechName:   IP Customer Care
OrgTechPhone:  +1-888-613-6330
OrgTechEmail:  harishbhavsar@att.com

OrgTechHandle: IPSWI-ARIN
OrgTechName:   IP SWIP
OrgTechPhone:  +1-888-613-6330
OrgTechEmail:  swipid@icorefep2.noc.att.com

OrgTechHandle: GIS3-ARIN
OrgTechName:   GMIS IP SWIP
OrgTechPhone:  +1-404-962-5160
OrgTechEmail:  rm-att-gmis-ipreg@ems.att.com

OrgTechHandle: DRU40-ARIN
OrgTechName:   Rueegg, Daniel
OrgTechPhone:  +41 1 4957899
OrgTechEmail:  drueegg5@agns.ch

# ARIN WHOIS database, last updated 2008-10-07 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
0
 
LVL 32

Assisted Solution

by:harbor235
harbor235 earned 250 total points
ID: 22670598

Port scanning is not against the law, I would however review your site's security posture and ensure that you have things locked down. If you continue to get scans someone is looking to find a way in. Now is a good time to do security assessment and even do a port scan your self from outside your network and see what the scanners are seeing.

Like belowzerotech posted above, you should also send an email to abuse@att.net. ATT has a very robust security depatment and I sure they can at least look into the source since it is within their network(s).

harbor235 ;}
0
 

Author Closing Comment

by:willsherwood
ID: 31504299
thanks!
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

You cannot be 100% sure that you can protect your organization against crypto ransomware but you can lower down the risk and impact of the infection.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now