cancel
Showing results for 
Search instead for 
Did you mean: 

Multiple Attempts on Firewall log from Plusnet?

N/A

Multiple Attempts on Firewall log from Plusnet?

I was bored and read through my firewall log just now. I was VERY suprised to see several attempted connections being made from Plus.com hostnames.

Example:

2005/08/31 23:16:42 80.229.162.242:2098 (rockychamp01.plus.com) 80.229.222.11:445 Microsoft-DS
2005/08/31 23:15:34 80.229.162.242:4565 (rockychamp01.plus.com) 80.229.222.11:139 NETBIOS Session
2005/08/31 23:15:24 80.229.163.167:4290 (calvin1.plus.com) 80.229.222.11:445 Microsoft-DS
2005/08/31 23:06:24 80.229.157.172:4846 (bjames.plus.com) 80.229.222.11:139 NETBIOS Session
2005/08/31 23:04:43 80.229.157.172:1902 (bjames.plus.com) 80.229.222.11:139 NETBIOS Session
2005/08/31 22:57:57 84.93.21.56:3586 (84.93.21.56.plusnet.ptn-ag1.dyn.plus.net) 80.229.222.11:135 DCE endpoint resolution

A very small example!

Whats going on?!
4 REPLIES
N/A

Multiple Attempts on Firewall log from Plusnet?

they are either:

1) port scanning you

2) could have a virus on their machines

3) i suppose you don't know them or they could be on msn or something similar - talking to you etc

more likely to be 2) tho

hope this helps
Community Veteran
Posts: 14,469
Registered: 30-07-2007

Multiple Attempts on Firewall log from Plusnet?

6 hits in 20 minutes is nothing to worry about.

What you are seeing is the normal 'internet noise' from infected systems or MS trying to find other systyems in the originators workgroup.

Your firewall is doing it's job as expected and is safe to ignore. If you were getting 100s of hits during that period then you need to report it but 6 is nothing.
N/A

Multiple Attempts on Firewall log from Plusnet?

quite possible a virus but why loads of Plusnet connections and not much of anything else and all in a couple of hours?
Community Veteran
Posts: 14,469
Registered: 30-07-2007

Multiple Attempts on Firewall log from Plusnet?

Because PlusNet block ports on the perifery of their ntwork to stop such activity from the outside world getting into the PlusNet network. So you will see the majority of this traffic from PN systems.