<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Message about scanning for vulnerable ports in Everything else</title>
    <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956116#M34182</link>
    <description>&lt;P&gt;I know! That's what I thought. But I can see it in my notifications on the member centre home page. It's on the "help assistant" at &lt;A href="https://www.plus.net/wizard/" target="_blank" rel="noopener"&gt;https://www.plus.net/wizard/&lt;/A&gt; which I see says you can no longer ask a question, but that's how the message was sent to me and I can get back to it through that notifications bell. The message below is is all the information I have been given... (names removed)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Dear X,&lt;BR /&gt;&lt;BR /&gt;We have received reports that a PC using your IP address has been scanning other networks looking for vulnerable ports.&lt;BR /&gt;&lt;BR /&gt;The most likely explanation for this is that you are infected with a virus. Please disinfect your system, and then inform us using the Help Assistant in the customer portal (&lt;A href="http://portal.plus.net/wizard/index.html" target="_blank" rel="noopener"&gt;http://portal.plus.net/wizard/index.html&lt;/A&gt;, click on Customer Services &amp;amp; Billing) that you have done so.&lt;BR /&gt;&lt;BR /&gt;We do not recommend a specific anti-virus product, but one freely available virus checker is AVG AntiVirus, available from &lt;A href="http://www.grisoft.com/" target="_blank" rel="noopener"&gt;http://www.grisoft.com/&lt;/A&gt; . Other free and commercially offered products are also available.&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;BR /&gt;&lt;BR /&gt;Y&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Wed, 31 Jan 2024 04:29:03 GMT</pubDate>
    <dc:creator>mike2843</dc:creator>
    <dc:date>2024-01-31T04:29:03Z</dc:date>
    <item>
      <title>Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956087#M34179</link>
      <description>&lt;P&gt;Hi, a few days ago I recieved a message on the help assistant saying that "We have received reports that a PC using your IP address has been scanning other networks looking for vulnerable ports". I replied asking for more information so I can look into it, but I haven't had any answer, so I have no details about what happened or when, I dont even know if it's still ongoing. I did find my address on an abuse website with reports up to about a week ago, but I don't know if it was actually my address at the time. Obviously I want to fix the problem so I don't get out internet cut off. Would there happen to be anyone around here that could help out find me some more details?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 21:19:26 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956087#M34179</guid>
      <dc:creator>mike2843</dc:creator>
      <dc:date>2024-01-30T21:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956092#M34180</link>
      <description>&lt;DIV style="background: #EDF3F5; padding: 10px; margin-top: 10px; margin-right: 10px; border: 2px solid #CFD8DC; border-radius: 10px; box-shadow: 8px 8px 7px #676D70; font-size: 12px;"&gt;&lt;STRONG&gt;Moderator's note:&lt;/STRONG&gt;&lt;BR /&gt;Thread moved from Full Fibre to Everything Else&lt;/DIV&gt;</description>
      <pubDate>Tue, 30 Jan 2024 21:24:33 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956092#M34180</guid>
      <dc:creator>Baldrick1</dc:creator>
      <dc:date>2024-01-30T21:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956103#M34181</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;&amp;nbsp;a few days ago I recieved a message on the help assistant"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What help assistant and from what email address?&amp;nbsp; Are you sure it came from Plusnet?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sounds a little scamy!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 00:26:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956103#M34181</guid>
      <dc:creator>Townman</dc:creator>
      <dc:date>2024-01-31T00:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956116#M34182</link>
      <description>&lt;P&gt;I know! That's what I thought. But I can see it in my notifications on the member centre home page. It's on the "help assistant" at &lt;A href="https://www.plus.net/wizard/" target="_blank" rel="noopener"&gt;https://www.plus.net/wizard/&lt;/A&gt; which I see says you can no longer ask a question, but that's how the message was sent to me and I can get back to it through that notifications bell. The message below is is all the information I have been given... (names removed)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Dear X,&lt;BR /&gt;&lt;BR /&gt;We have received reports that a PC using your IP address has been scanning other networks looking for vulnerable ports.&lt;BR /&gt;&lt;BR /&gt;The most likely explanation for this is that you are infected with a virus. Please disinfect your system, and then inform us using the Help Assistant in the customer portal (&lt;A href="http://portal.plus.net/wizard/index.html" target="_blank" rel="noopener"&gt;http://portal.plus.net/wizard/index.html&lt;/A&gt;, click on Customer Services &amp;amp; Billing) that you have done so.&lt;BR /&gt;&lt;BR /&gt;We do not recommend a specific anti-virus product, but one freely available virus checker is AVG AntiVirus, available from &lt;A href="http://www.grisoft.com/" target="_blank" rel="noopener"&gt;http://www.grisoft.com/&lt;/A&gt; . Other free and commercially offered products are also available.&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;BR /&gt;&lt;BR /&gt;Y&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 31 Jan 2024 04:29:03 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956116#M34182</guid>
      <dc:creator>mike2843</dc:creator>
      <dc:date>2024-01-31T04:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956132#M34183</link>
      <description>&lt;P&gt;Ah, OK that’s sound.&lt;/P&gt;
&lt;P&gt;”Help centre” is legacy PlusNET space for managing support issues aka the ticketing system. &amp;nbsp;You cannot raise new tickets, but you can respond to them.&lt;/P&gt;
&lt;P&gt;It does sound as though you have a virus or malware on your computer - what antivirus product do you use?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 08:40:27 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956132#M34183</guid>
      <dc:creator>Townman</dc:creator>
      <dc:date>2024-01-31T08:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956280#M34207</link>
      <description>&lt;P&gt;Ah ok, it looked like that with the help centre. I did respond to the ticket since it let me. Is anyone going to see that?&lt;/P&gt;
&lt;P&gt;It's all Linux computers and Android phones so I haven't really got any antivirus. I've got OpenWRT running so I'm using tcpdump to watch out for anything going out on high port numbers or port 22 now. The abuse website mentioned attempted SSH logins but no idea if I had the address at the time. No idea if trying to find vulnerable SSH servers would be included in "scanning for vulnerable ports". Not ideal but it should pick up that and port scans.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 23:38:46 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956280#M34207</guid>
      <dc:creator>mike2843</dc:creator>
      <dc:date>2024-01-31T23:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Message about scanning for vulnerable ports</title>
      <link>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956287#M34209</link>
      <description>&lt;P&gt;Linux and Android are not immune to malware and virus attack - in fact I'd suggest that they are equally prone if not more so - Linux is a hackers playground!&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.malwarebytes.com/blog/detections/linux-hacktool-portscan#:~:text=Port%20scanners%20are%20often%20used,facilitating%20more%20complex%20cyber%2Dattacks." target="_blank"&gt;Linux.Hacktool.Portscan (malwarebytes.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 02:27:04 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/Message-about-scanning-for-vulnerable-ports/m-p/1956287#M34209</guid>
      <dc:creator>Townman</dc:creator>
      <dc:date>2024-02-01T02:27:04Z</dc:date>
    </item>
  </channel>
</rss>

