10 ms·
Server.casino – Random Servers Across the Internet
- asplake 5y agoUm, not sure I want to open that link. What does it do?
- aphroz 5y agoIt returns you a random server with port 80 or 443 open.
- savolai 5y agoNot before you push the button on the page though.
- wfriesen 5y agoJust 80, it seems https://github.com/caioluders/server.casino/blob/354cec4c0532c6e94bcff70e66e639b5d49a546e/js/casino.js#L25 https://github.com/caioluders/server.casino/blob/354cec4c053... That probably increases the odds that the servers it finds are "interesting"
- CountDrewku 5y agoNot really.... almost all web servers with 443 will have port 80 open to function. Current browsers all still hit 80 first.
- bellyfullofbac 5y agoHuh, press the "Find a Server" button, I can see in Developer Console it tries to connect to random IP addresses over http, returning "address invalid" or "address unreachable", I guess until it hits a valid IP with a live computer. I wonder if some ISP's heuristics will flag someone's computer as part of a botnet...
- hsbauauvhabzb 5y agoMicrosoft or AWS may also use telemetry to flag you also.
- g3ol4d0 5y agoNever thought of this. I constantly scan the internet using nmap, or similar, for pentest/bug bounty and never had a problem
- ALittleLight 5y agoHow are you pentesting without knowing the IPs of your in-scope targets?
- sodimel 5y agoHere's the source: https://github.com/caioluders/server.casino https://github.com/caioluders/server.casino
- bnajdecki 5y agoScary - I get some strange URL that encouraged me to install some CSS plugin. How do you random those names? Are they only some random IPs? BTW. some history would be nice, as I couldn't find this server again :(
- mobilio 5y agoLike Chatrubate, but with servers? #sarcasm
- jenoer 5y agoI think you mean Chatroulette.
- emilfihlman 5y agoNah, both exist.
- somethingor 5y agoThat doesn’t mean both are apt comparisons
- hsbauauvhabzb 5y agoIANAL but I would caution accessing these, they may constitute hacking in your local region. I would doubly caution owning this, particularly given the wording on the site encourages messing with people’s servers…
- pdenton 5y agoIt found http://127.249.137.9 http://127.249.137.9 for me and it totally works! I can even ssh to it, let's try a fork bo^#@~ [connection reset by peer]
- YellowSuB 5y agoI also found that on my end, forgot I was running lighthttpd with some test website.
- yayr 5y agofunction randomIP() { return int2ip(Math.random()\*4294967296) ; } says it all - better don't "mess" with what you encounter
- allarm 5y agoIt doesn't even exclude RFC1918 and multicast addressses. Not really efficient.
- indigodaddy 5y agoThis is an extremely bad idea. Your chances of getting some malware are probably more likely than not, after playing around with something like this for 10+ minutes...
- Miner49er 5y agoHow? The odds of hitting a site with a browser 0-day has to be extremely low, certainly not "more likely than not". Sure you might hit sites that try to get you to download malware, but just don't download anything.
- syoc 5y agoHalf the struggle in exploiting someone behind NAT/FW is getting them to engage with your infrastructure. Your attack surface is massively increased once you visit a website with your browser for instance. I see other comments mentioning logging into random IPs over ssh. Now i trust the ssh client implementation more than most software, but it's easy to slip up and enable ssh agent forwarding for instance.
- Arafen 5y agoIt was not for nothing that I realised in time that stock exchanges and quotations were not for me. I could not make any money on the ups and downs of exchange rates. But I managed to make an online betting application with the help of Nuxgame with their engine https://nuxgame.com/products/sport-engine https://nuxgame.com/products/sport-engine . I was able to set everything up very quickly and even made my first money.
- dannyw 5y agoDO NOT DO THIS. I have a few servers exposed on IP addresses, but they are not meant for public access. You have no authorization for 'messing' with this site: what you deem playing around, might be hacking. You may also hit a government or military IP address, known or unknown. If you mess around with them, you may receive some unfriendly visits from men in black.
- nullify88 5y agoIf its on the public internet with no security, how can someone tell if their access is unauthorised? Its not really that different from connecting to facebook.com or the various publically accessible ssh servers.
- fortyseven 5y agoYou have unprotected servers public facing on the internet? Cool. That's definitely not something you should be concerned about and addressing immediately.
- generalizations 5y ago> they are not meant for public access Then, I think, you need to implement "reasonable measures" to secure them. Otherwise it's like putting your stuff out by the curb.
- celesian 5y agoI mean, your IP is being crawled by random bots dozens of time per day, what's the difference between that website and the traffic your IP gets already?
- 35fbe7d3d5b9 5y agoSeriously, this is a laughable concern – if you have a "public facing server" you're already listed in Google, Shodan, being probed by dozens of IPs across the world...
- nonbirithm 5y ago
- don-code 5y agoI'm waiting for someone to get our corporate VPN on a blacklist just by clicking the button and hitting a honeypot. Granted, it's what I get for hitting the button without reading the code, so, shame on me?