User comments on ISPs
  >> Sky Broadband


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User Squirrel
(fountain of knowledge) Mon 29-Jan-07 22:50:30
Print Post

Thoughts on Sky's "Network"


[link to this post]
 
Since moving to Sky Broadband my firewall has been very quiet, very quiet indeed. Here is my IPTABLES log from yesterday


--------------------- iptables firewall Begin ------------------------


Denied 4 packets on interface eth0
From 0.0.0.0 - 3 packets to udp(67)
From 66.98.224.53 - 1 packet to tcp(22)

Logged 72 packets on interface ppp_0_38_1
From 80.127.5.47 - 14 packets to tcp(47241)
From 87.67.141.12 - 1 packet to tcp(139)
From 90.186.109.215 - 1 packet to tcp(135)
From 90.197.218.143 - 50 packets to tcp(135)
From 211.24.144.6 - 2 packets to tcp(445)
From 220.216.40.107 - 4 packets to tcp(1023,9898)

---------------------- iptables firewall End -------------------------

The first section shows people who have got through the open ports on my firewall and made direct attacks on my systems - 1 address. The second section is people who have probed my router and got rejected - usually virus attacks and stale P2P sessions started by the previous owner of my DHCP address. In this case there is just a few users.

When on Bulldog these two sections would be pages long - my box was constantly under direct attack and the Bulldog network was riddled with virus infected machines.

Why is Sky different ????

Ian Stirling

Bulldog Communications 8Mb Inter@ctive
Standard User deleted
(deleted) Tue 30-Jan-07 10:31:09
Print Post

Re: Thoughts on Sky's "Network"


[re: Squirrel] [link to this post]
 
Why is Sky different ????

It insists that everyone uses a NAT router with a stateful packet inspection firewall.

That means that no-one on their network is using a nasty USB modem with no firewall. Leads to fewer bot-net victims to bombard the network with viruses, trojans etc.

Sky is a bit like a totalitarian state. "At least under Stalin the trains ran on time". Fine until you try to leave...

Edited by deleted (Tue 30-Jan-07 10:34:02)

Standard User deleted
(deleted) Tue 30-Jan-07 11:41:07
Print Post

Re: Thoughts on Sky's "Network"


[re: deleted] [link to this post]
 
Sky is a bit like a totalitarian state. "At least under Stalin the trains ran on time". Fine until you try to leave...

Excellent, that did make me laugh - on a slightly serious note; I did ask Sky where they sit on people leaving the EasyNet network on LLU in 12-months time, as they have replied [in writing] that there will be no issues in giving LLU Mac keys: I suppose time will tell

Blue


Register (or login) on our website and you will not see this ad.

Standard User jchamier
(experienced) Tue 30-Jan-07 22:50:24
Print Post

Re: Thoughts on Sky's "Network"


[re: Squirrel] [link to this post]
 
Interesting stuff. Can't be NAT routers can it, as bots tend to sit attached to an IRC channel waiting for commands, and then connect out. (Unless the NAT router is also outbound firewalling).

I wonder if the IP ranges are still new, and haven't been "infected" yet?

--
James on Bulldog Unlimited Plus (ADSL2+) - SpeedTouch 516v6 (sw=v5) & Draytek 2900VG
18mbps reliable sync - DMT: July06 / Jan07 - 820m from exchange
Standard User Squirrel
(fountain of knowledge) Tue 30-Jan-07 23:26:44
Print Post

Re: Thoughts on Sky's "Network"


[re: jchamier] [link to this post]
 
In reply to:

I wonder if the IP ranges are still new, and haven't been "infected" yet?



I was thinking along those lines too. The NAT routers supplied by Sky, which are probably the ones being used by the less PC savvy, hence those likely to be infected, don't stop outbound traffic flow.

On Bulldog the direct attacks I saw were mainly from Chinese and far eastern IP addresses. The virus attacks came predominantly from within the Bulldog network, which implies Bulldog are filtering known virus ports at the edge of their network (because infected machines are definitely out there).

Now on Sky I see no attacks from China (probably newly allocated IP ranges as you said) and virtually no virus attacks. To me that seems to imply Sky are filtering within their own networks as well as at the internet gateways.

Ian Stirling

Bulldog Communications 8Mb Inter@ctive
Standard User skalpel
(learned) Tue 30-Jan-07 23:46:41
Print Post

Re: Thoughts on Sky's "Network"


[re: Squirrel] [link to this post]
 
On almost any network the vast majority of attacks you see will be from the local network - most network-scanning worms are set to probe "local" IP addresses preferentially. The Formula used by Code Red (and replicated in most other worms) is 25% of the time spent scanning the local /24 (255 addresses), 25% on the local /16 (65535 addresses), 25% on the local /8 (1.6 million IPs) and 25 % on the entire internet (4.2 billion addresses).

"Local" is determined by the IP address of the infected machine - which is the other reason you;ll see so few Sky users scanning you, because (in theory at least) they're all on 192.168.0.0/24, so they'll only be spending 25% of their time scanning in a range that includes Sky's external range - and that will be diluted by being just a few hundred thousand addresses in billions.

I do feel sorry for the owners of legitimate routable networks in 192.0.0.0/8 though, as they get absolutely *hammered* every time a new network worm starts up.

Of course, there's also the fact that network scannign has been on the wane for a few years now - the fact that Windows XP SP2's firewall actually *works* has led to crackers shifting from network scanning (which is noisy and easy to stop) to application-based attacks (on Internet Explorer, Office, Windows Media Player, etc, etc, etc, etc...) via email, instant messaging, web, and (predominately) P2P networks.

There's also been a big dropoff in network abuse generally in the last month - a combination of restricted routing to Taiwan and China for a few weeks after the earthquake on boxing day knowcked out a bunch of fibre, the general downturn of 'net use during the Christmas and New Years breaks, and a couple of big botnets have been taken down in the past two weeks.
Standard User deleted
(deleted) Wed 31-Jan-07 12:01:43
Print Post

Re: Thoughts on Sky's "Network"


[re: skalpel] [link to this post]
 
from what Ive seen so far Skys IPs start 90.x.x.x now Ive never seen an IP starting with 90 before or maybe Im not looking closely enough.

Standard User frontieruk
(committed) Wed 31-Jan-07 12:11:17
Print Post

Re: Thoughts on Sky's "Network"


[re: deleted] [link to this post]
 
I was offered my LLU MAC after Sky thought they couldn't solve an issue I was having, I declined the offer, two days later the problem was solved but I had been offered a way off the network.

-- Sky Maxed... High speed... High pings... Bad gaming
PC:- AMD 64 x2 4200

Now Playing :-
Amped 3, BF2:MC, Burnout Revenge, CoD2, CoD3, DOA4, FN3, GoW, GW:AW, Kameo, Oblivion, Over G Fighters, PDZ, PES6, PGR3, RB6:V, Rockstar Table Tennis, RR6, TS2 see you on LIVE
Standard User jchamier
(experienced) Wed 31-Jan-07 22:06:38
Print Post

Re: Thoughts on Sky's "Network"


[re: Squirrel] [link to this post]
 
You would have thought that scanning bots/progs would query a default gateway to see if it supports UPNP (its xml I gather) and setup port forwarding. Its only going to be time.


--
James on Bulldog Unlimited Plus (ADSL2+) - SpeedTouch 516v6 (sw=v5) & Draytek 2900VG
18mbps reliable sync - DMT: July06 / Jan07 - 820m from exchange
  Print Thread

Jump to