31 ms·
Maybe that's a case, but their abuse team hasn't replied anything in a 2 weeks about that after I gave them all timestamps and both source/destination IP addres
by jimsi 5y ago
Maybe that's a case, but their abuse team hasn't replied anything in a 2 weeks about that after I gave them all timestamps and both source/destination IP addresses
- vadfa 5y agoThey won't disconnect clients over SSH scanning. That's a ridiculous expectation. It's 2021. Nobody cares.
- brohee 5y agoWhat kind of answer would you expect, in all seriousness? The thing you are reporting is not illegal or even dodgy.
- jimsi 5y agoI expect to hear who (and why) generates that kind of traffic from cloudflare owned subnets.
- tux3 5y agoI can understand your frustration with background internet noise, but please note Cloudflare is not known for broadcasting their customers' names to the first abuse report with a pcap of a TCP handshake. There may be more realistic ways to go about protecting people's SSH servers that trying to dox Cloudflare VPN users.
- Hrundi 5y agoWho's trying to dox those users?
- tux3 5y agoI assumed OP wants to know the identity of the Cloudflare users scanning their SSH ports. I think OP guessed it was probably not Cloudflare themselves scanning their ports, so I think that's what they meant by "hear who and why". Maybe dox is too strong a word. My point is, from what I've heard, the general sentiment is that you're unlikely to get any information about customers just by sending abuse reports to Cloudflare.
- chmike 5y agoOP obviously simply expected at least an explanation on the cause of these ssh connection probes. He got the explanation here (VPN).
- that_guy_iain 5y agoI can‘t understand it. There doesn‘t appear to be any downside or even abuse happening. The fact OP expects a company to explain who and why a customer of theirs did a legal non abusive act is just an outstanding level of entitlement.
- deleted 5y ago[deleted]
- marginalia_nu 5y agoVPS and VPN providers should be very mindful of their reputation in this regard. If they get a reputation as a "black hole" where complaints vanish and nothing ever happens, the effect may be that other customers start to find themselves blocked or throttled on a subnet level.
- eli 5y agoI don’t know of any provider that would take action on reports of ssh scanning.
- TechBro8615 5y agoA little bird told me a story that AWS will forward abuse reports to customers performing outbound nmap scans.
- sleepybrett 5y agoI report them from time to time. I'm not sure why people don't take them seriously. If 500 people a day came up to your front door and tried the knob, hell maybe even tried a couple of keys in the lock... I'm pretty sure you'd be calling the cops.
- eli 5y agoAn ssh server isn’t really like a front door though. I don’t necessarily think attempting a random ssh server should be a crime. I used to spend time on custom iptables scripts but came to the conclusion it’s much better to just architect things in a way where the bots and scanners can’t plausibly create a problem and then ignoring them.
- TechBro8615 5y agoI don’t think anyone is about to block or throttle traffic from Cloudflare IP ranges.
- marginalia_nu 5y ago
- miyuru 5y agoIf your ISP and the server support IPv6, just disable SSH on IPv4. Some of my servers don't even have any IPv4 connectivity and there haven't been any failed SSH logins over IPv6.
- jimsi 5y agoMy OpenSSH is located on a non standard port, 22/tcp is going to the endlessh honeypot.
- zinekeller 5y agoNot to disappoint you, but except for logging SSH honeypots are becoming useless (most bots automatically disconnect when they detect a long login banner).
- sudobash1 5y agoSo should I add a long banner to my server to disguise it as a honey pot, just in case?
- zinekeller 5y agoI mean, I'm not sure that you can do that with OpenSSH though (short of recompiling it, which I do not recommend unless you're a company).
- throw0101a 5y ago> endlessh honeypot. *tarpit A honeypot lets people "in" to see/research malware that's in the wild: * https://en.wikipedia.org/wiki/Honeypot_(computing) https://en.wikipedia.org/wiki/Honeypot_(computing) A tarpit just takes up the attacker's resources: * https://en.wikipedia.org/wiki/Tarpit_(networking) https://en.wikipedia.org/wiki/Tarpit_(networking)
- judge2020 5y agoNot what most people run, but SSH honeypots are also useful: https://lwn.net/Articles/848291/ https://lwn.net/Articles/848291/