3 ms·
Thank you! I've been self-hosting for about a year running a 400-line http/s server of my own design, and it's remarkable all the attacker traffic my 3 open por
by simpaticoder 3y ago
Thank you! I've been self-hosting for about a year running a 400-line http/s server of my own design, and it's remarkable all the attacker traffic my 3 open ports (22, 80, 443) get, although I've never taken the time to analyze what the attackers are actually trying to do! This post fills in a LOT of blanks.
Would be cool to do the same thing for the weird stuff I see in /var/log/auth.log!
It's crazy that attackers would bother with me since the code is entirely open source and there is no server-side state. The best outcome for an attacker would be root access on a $5/mo VPS, and perhaps some (temporary) defacement of the domain. A domain no-one visits!
- epcoa 3y agoThese are all automated bots. No one is “bothering”. You open the 3 most well known ports you’re going to get connections. They don’t know what you’re running nor do they care.
- simpaticoder 3y agoBy "bothering with me" I mean "add my IP to the long list of IPs they are scanning". By the way, I find it annoying that my logs get filled with this kind of trash. It has the perverse effect of making me long for something like Google Analytics since they rarely if ever bother running a javascript runtime.
- epcoa 3y agoThat long list isn’t curated, it’s every publicly routable IPv4 address. It really does not take long to run some canned probes against 3.7 billion addresses. Making your service IPv6 only tends to cut down on this traffic. You’re anthropomorphizing a script on some botnets.
- ericpauley 3y agoThis isn’t entirely true. Many scanners do preference specific IP ranges such as cloud providers. Cloud IPs receive substantially more scanning traffic than darknet IPs or even random corporate IPs.
- deleted 3y ago[deleted]
- iramiller 3y agoIPv6 only? If you have a DNS record for that your are still not making it very difficult for scripts to find you.
- epcoa 3y ago> If you have a DNS record for that your are still not making it very difficult for scripts to find you. If you put your ssh server or something on an uncommon subdomain how will these scripts find it? If you are on @ or some common name sure, otherwise no.
- ozim 3y agoNo one is maintaining a list they just scan all. Scanning every IPv4 there is on a single port takes minutes.
- dotancohen 3y agoAccess to your VPN is a great way to launch attacks on other machines, and to add another layer to covering his tracks. Not to mention hosting malware to be downloaded to other places, and even a crypto miner.
- mianos 3y agoI set up a honeypot once and logged the passwords of created accounts. I then used 'last' to find the incoming ip. I then used ssh to try and connect to the originator (from an external box). I went back 5 jumps until I got to a windows server box on a well known hosting service that I could not get into. Lots of what looked like print servers and what looked like linux machines connected to devices. Maybe just the exploit at the time.
- icameron 3y agoConsider blocking 22 except whitelist your own IP. My ISP changes my IP rarely in practice and when they do I can log into the hosting web admin panel and update the rule.
- petee 3y agoJust accept key-only logins, everything else becomes noise. I also limit concurrent connections, which significantly reduces data usage during aggressive attacks