4 ms·
On average about 100 (TCP) requests hit my home router per minute doing various probing and scanning. Lots of checking for the telnet port obviously. Sometimes
by binaryturtle 2mo ago
On average about 100 (TCP) requests hit my home router per minute doing various probing and scanning. Lots of checking for the telnet port obviously. Sometimes you can see a swarm of entirely different IPs scanning the full port range (probing the ports one-by-one).
You'll see a lot of deepfield, censys-scanner, visionheight.com, shadowserver.io, etc., but also the usual suspects of Chinese or Russian IPs.
With OpenWRT I use something like this: `tcpdump -i pppoe-wan 'inbound and tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn'`, or alternatively `tcpdump -i pppoe-wan 'inbound and tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn and not port 44000'`, if we have some torrent client running (e.g. here at port 44000) which would mess up the result. I'm not sure it's the best way to handle this, but it's definitely enlightening what bounces off on the router.
- miah_ 2mo agoThe easiest way to deal with the usual suspects is to just block the entire countries network range(s). There really is no reason they should be connecting to your home router anyway, and you lose nothing from blocking them. Sure their packets will still hit your router, but if they are dropped immediately at least you're not wasting a syn-ack on them.
- tommyage 2mo agoI, temporarly, banned some ip range. I didn't find a source for pinpointing countries; though I am interested. Could you point me to some sources which, deterministically, resolve to some countries? To my knowledge you can not reliably identify countries by ip since this would be dependent on DNS servers. Though I am just a application programmer! Thanks in advance.
- Asmod4n 2mo agoRouters got such a thing build in nowadays, just gotta enable it (not the ones from your ISP of course)
- thesuitonym 2mo agoYour router doesn't care about their DNS settings. IP addresses are very easy to tie back to countries. The reason they say it's not reliable is because it's trivial to spoof the country, but even so, a lot of attackers don't even bother. It's sort of like the Nigerian prince scam calls: if you're wise enough to block Russia, you're not worth their time. Your firewall vendor should supply you with country lists, just select the known bad ones and drop their traffic. If you have a consumer grade router, you will probably have to configure the blocklists manually.
- lostlogin 2mo agoI wonder if adding the US is now sensible.
- thesuitonym 2mo agoUnless you're serving something, you should probably drop all incoming requests. If you are serving something, the US is a pretty big market to lock yourself out of.
- inigyou 2mo agoAlmost all spam traffic comes from the US, it's not even close. But for many people so does much of their human traffic.
- 0points 2mo agoFWIW, I blocked the US for a while. Eventually, my lets encrypt cert expired and it turns out certbot is run from USA, so the auto renewal failed me.
- numpad0 2mo ago> The reason they say it's not reliable is because it's trivial to spoof the country ISPs sometimes do trade IPv4 blocks and countries to which it belongs do change occasionally. That can become a problem if you were like literally Netflix and someone few nation states over started an ISP.
- random29ah 2mo agoGetting it directly from IANA is always the best approach. Here is a "simplified" version in various formats. https://github.com/HotCakeX/Official-IANA-IP-blocks https://github.com/HotCakeX/Official-IANA-IP-blocks
- inigyou 2mo agoGross - you're going to block countries just because the US government doesn't like those countries?
- ShinyLeftPad 2mo agoDo you think you get excluded from mass scans for disagreeing with your government?
- Jskewel 2mo agoI'm happy to unblock China from accessing my website, once China does something about the millions of daily hack attempts originating from that country.
- inigyou 2mo agoBut you pointed to a list of OFAC sanctioned countries, not China.
- supermatt 2mo ago> just block the entire countries network range(s) Why not just block all the inbound connections you don't need? Is there a particular reason your firewall policy needs to be xenophobic?
- mzajc 2mo ago> The easiest way to deal with the usual suspects is to just block the entire countries network range(s). Keep in mind that this should be paired with an ASN blacklist - MaxMind also has an ASN mmdb for convenience - because IP address to country maps are almost entirely self-declared[0]. For example, Tencent (AS132203), which you almost certainly want to block, has ranges in 73 different countries per [1]. [0]: https://datatracker.ietf.org/doc/html/rfc8805 https://datatracker.ietf.org/doc/html/rfc8805 [1]: https://bgp.tools/as/132203#prefixes https://bgp.tools/as/132203#prefixes
- impish9208 2mo agoI can corroborate visionheight and shadowserver from my firewall logs.
- sroussey 2mo agoI have ubiquity UniFi for this reason (amongst others). OpenWRT is a good choice as well. Most home router software is such junk, might as well leave the door open..
- heywire 2mo agoThis is one reason I don’t mind that I’m behind CGNAT.
- binaryturtle 2mo agoThat's the only advantage of CGNAT I can think of. :D (You still could get poked from the other users' hosts behind the ISP's NAT, of course.)
- itsTyrion 2mo agoan angry skid in a game can't (D)DoS your router might be one. I'd still prefer to not have CGNAT
- protocolture 2mo agoDepends if the ISP has client isolation of one method or another enabled.
- hahahaa 2mo agofail2ban?