I haven't had a great deal of trouble from people port scanning me in the past, so it seems odd to me when I have got scanned 28 times in the past 3 days. Some of you will laugh because this seems normal, but it just seems odd that its been in the past few days.

I'm running Windows XP Pro and using Sygate as my firewall, here is a snippet from the logs:

03/14/2004 07:04:20 Port Scan Minor Incoming TCP 68.16.128.2 00-50-57-00-EF-5F xxx.xxx.xxx.xxx my mac addy thadbme PEREGRIN Normal 1 03/14/2004 07:04:20 03/14/2004 07:04:20

These scans are coming in groups of three, and scanning for ports 2745, 1025, 3127, 6129 and 5000. What I mean by groups of three is the at three scans will appear within 10 seconds. So it appears that they are scanning for MyDoom, Beagle, and a few other ports.

Most of the scans appear to be coming from my home ISP, which is cox, but the excerpt that I gave you is from bellsouth.

Anyways, my question is whats the ethical thing to do here? Several of the scans came from the same address. I have reported that address to abuse@cox.net. But I got one of those auto reply messages. And I fear its one of those messages where they think I'm paranoid or something.

I can't continue to mail the abuse address for all of the isp's as that would get out of hand quickly. And I realize that fighting back to some measure wouldn't be correct either. Any ideas? Also any idea why there would be a sudden increase in the past two days?