Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: 1 [2] 3

Author Topic: Public IP addresses and port scans  (Read 10854 times)

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5289
    • Thinkbroadband Quality Monitors
Re: Public IP addresses and port scans
« Reply #15 on: January 25, 2023, 12:58:56 PM »

The OS guesses are weird, given its actually running kernel 6.0.18, so no idea how its trying to figure that out.  I guess its a good thing it can't identify it though.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

XGS_Is_On

  • Reg Member
  • ***
  • Posts: 479
Re: Public IP addresses and port scans
« Reply #16 on: January 25, 2023, 09:04:53 PM »

It's usually looking at the TCP stack, sequence numbers, etc as far as OS fingerprinting goes.
Logged
YouFibre You8000 customer: symmetrical 8 Gbps.

Yes, more money than sense. Story of my life.

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5289
    • Thinkbroadband Quality Monitors
Re: Public IP addresses and port scans
« Reply #17 on: January 26, 2023, 12:46:41 AM »

So how is it getting it wrong?

Mind you, I'm surprised it only shows "xmpp-client?" as surely an XMPP server should be pretty easy to identify?  It seems to recognise the XMPP Proxy service definitively, I guess that sticks more rigid to the standard.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7411
  • VM Gig1 - AAISP CF
Re: Public IP addresses and port scans
« Reply #18 on: January 26, 2023, 07:02:51 AM »

Interestingly I turned on logging for default block rule on a server to diagnose an issue, and the thing is been hit by about 30 ip's every minute just constant port scans. :)
Logged

XGS_Is_On

  • Reg Member
  • ***
  • Posts: 479
Re: Public IP addresses and port scans
« Reply #19 on: January 26, 2023, 07:54:47 AM »

Place a URL going back to it on a public forum as I did to catch out a fantasist. You get lots of interesting sources for HTTP requests and some quite interesting HTTP requests like bots trying http://hostname/../../../.. /.. /etc/passwd

I think not.  :)
Logged
YouFibre You8000 customer: symmetrical 8 Gbps.

Yes, more money than sense. Story of my life.

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5289
    • Thinkbroadband Quality Monitors
Re: Public IP addresses and port scans
« Reply #20 on: January 26, 2023, 04:39:46 PM »

Place a URL going back to it on a public forum as I did to catch out a fantasist. You get lots of interesting sources for HTTP requests and some quite interesting HTTP requests like bots trying http://hostname/../../../.. /.. /etc/passwd

I think not.  :)

What sort of guano configured web server would actually respond to that?
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

XGS_Is_On

  • Reg Member
  • ***
  • Posts: 479
Re: Public IP addresses and port scans
« Reply #21 on: January 26, 2023, 10:35:09 PM »

Ones that haven't been chrooted.
Logged
YouFibre You8000 customer: symmetrical 8 Gbps.

Yes, more money than sense. Story of my life.

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5289
    • Thinkbroadband Quality Monitors
Re: Public IP addresses and port scans
« Reply #22 on: January 27, 2023, 03:02:35 AM »

Ones that haven't been chrooted.

Mostly old routers?
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

XGS_Is_On

  • Reg Member
  • ***
  • Posts: 479
Re: Public IP addresses and port scans
« Reply #23 on: January 30, 2023, 09:38:26 AM »

Really old stuff where the web service was installed as root, hence could reach everything, or had excessive privileges and no chroot on the user account so could go anywhere.

Really, really old stuff. Old routers aren't an issue, they don't have GUIs  :)
Logged
YouFibre You8000 customer: symmetrical 8 Gbps.

Yes, more money than sense. Story of my life.

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7411
  • VM Gig1 - AAISP CF
Re: Public IP addresses and port scans
« Reply #24 on: January 30, 2023, 09:40:20 AM »

The days before restrictive chrooted vhosts, open base dir and the like, I suspect there is a few really ancient stuff still out there.
Logged

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5289
    • Thinkbroadband Quality Monitors
Re: Public IP addresses and port scans
« Reply #25 on: January 30, 2023, 06:55:40 PM »

The days before restrictive chrooted vhosts, open base dir and the like, I suspect there is a few really ancient stuff still out there.

Yeah its probably just power plants, water treatment, you know all the really unimportant stuff they can't be bothered to update because "it works". ;)
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Public IP addresses and port scans
« Reply #26 on: February 05, 2023, 04:29:38 PM »

Quote
people get all freaked out about the idea of someone getting their public IP

I blame Steve Gibson for adding fuel to the fire on this.  His advice stuck and why shouldn't it?  He was a supposed security expert in the field.  :-\ 

Yeah he may have written a few interesting articles and given away a couple of handy tools for free, but he really went to town about IP disclosure and just downright scaring people saying "Look here, your IP address is x.x.x.x. and your rDNS is x.x.x.x.abc.com" claiming "It's really dangerous that so many websites know your IP"*  He scratched the surface on rDNS but never offered potential ways of minimising risk. 

20 years ago his site was extremely popular for doing quick port scan checks... people were getting DSL and using routers for the first time.   Shields Up was probably one of the best places to go........   

Except.. you landed on a page scaring you about potential risk because your IP and rdns available......  and then when you ran a test you failed because you had ICMP ping switched on.  Most router manufacturers set this to ON by default.  Vast numbers of problems materialised and some websites literally vanished off the face of the Internet.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5289
    • Thinkbroadband Quality Monitors
Re: Public IP addresses and port scans
« Reply #27 on: February 05, 2023, 07:39:17 PM »

Very much agree @kitz and I've seen other people say the same.

The funny thing is, few seem aware that by their nature web servers log your IP address for every lookup.  It would be an absolute nightmare to diagnose issues without such logs.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

burakkucat

  • Respected
  • Senior Kitizen
  • *
  • Posts: 38300
  • Over the Rainbow Bridge
    • The ELRepo Project
Re: Public IP addresses and port scans
« Reply #28 on: February 07, 2023, 11:15:10 PM »

There is one particular address that is incessantly port-scanning whatever public IPv4 address I might have. Why? Your guess is as good as mine as I'm not that interesting (as shown in my Reply #9, above).

Here is the persistent pest-address: 185.191.225.130

What I find amusing is that the 185.191.224.0/22 block is owned by Probe Networks, based in Germany. What else can I type other than "dummkopf".  :D
Logged
:cat:  100% Linux and, previously, Unix. Co-founder of the ELRepo Project.

Please consider making a donation to support the running of this site.

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7411
  • VM Gig1 - AAISP CF
Re: Public IP addresses and port scans
« Reply #29 on: February 10, 2023, 02:40:52 PM »

If I remember he had the shields up test to scan for open ports, ping response etc.

I think its now outdated, people able to ping you is no big deal and its an important means of diagnostics.  Plus ports that are NAT'd will be marked as open which will freak people out.
Logged
Pages: 1 [2] 3