Switch to IPv6 only and the port scans will go away. The address space is so big that port scanning is difficult, so the usual bots don't bother.
Sure but there are just some things you can’t run over ipv6
It wasn't a script kiddy. It wasn't even a human. You are going to be a very busy individual if you decide to report every port scan you find.
Uh sorry dude, but no this isn't a script kiddy, these are bots that scan every IP address every day for any open ports, it's a constant thing. If you have a public IP, you have people, govs, nefarious groups scanning it. AWS will tell you the same as if you were hosting it locally, close up the ports, put it on a private network. Use a vpc and WAF in AWS' case.
I get scanned constantly. Every hour of every day dark forced attempt to penetrate our defences.
You contacted Amazon over a port scan?
I have 750 bots stuck in HTTP tarpits right now, and another 13 stuck in an SSH tarpit.
You can fight back! If we all fight back just a little bit, then mass-scanning and scraping becomes too expensive to do.
Amen
If I showed you my WAN-side firewall logs you'd have a panic attack. I have a /29 block and about 10 scans tap one IP or another every second. It's part of being on the internet.
Your domestic home router experiences the exact same thing. Every moment of every day.
Will you report every scan? Every Chinese IP? Every US IP? It's completely common place to have someone 'knock on the door'.
Get off IPv4 anyway and onto IPv6. Good luck to them finding you by chance in there.
I ran a Tor relay on one of my spare servers for a while, and my god did that thing get port scanned. Even two years after I stopped hosting the relay, it was still getting pinged every 5-10 seconds (while my other servers tend to get pinged "only" once ever 20-30 seconds).
Remember to also report ssh login attempts and unauthorized wordpress access (even if wordpress isn't installed).
Also, all spam messages.
For SSH it will have to be attempted connections. Ain't no way I'm putting a forward facing SSH. I'll deal with any downtime that comes from not being able to access my server remotely
Haha, I get one of those every other day.
The sad reality of the Internet. Being the first for this new server feels like a "Welcome to the Internet, glad you are here" kind of message
I am reminded of a Richard Pryor skit in which he tells about a football player he knew who bit the fingers off of an opponent who was trying to gouge his eyes through his helmet. When Pryor asked him why he bit the guy's fingers off he said 'Everything outside the mask is his. Everything inside the mask is mine.'
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!