26
submitted 9 hours ago by [email protected] to c/[email protected]

Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

top 41 comments
sorted by: hot top new old
[-] [email protected] 7 points 3 hours ago

Switch to IPv6 only and the port scans will go away. The address space is so big that port scanning is difficult, so the usual bots don't bother.

[-] [email protected] 2 points 2 hours ago

Sure but there are just some things you can’t run over ipv6

[-] [email protected] 67 points 7 hours ago

It wasn't a script kiddy. It wasn't even a human. You are going to be a very busy individual if you decide to report every port scan you find.

[-] [email protected] 45 points 8 hours ago

Uh sorry dude, but no this isn't a script kiddy, these are bots that scan every IP address every day for any open ports, it's a constant thing. If you have a public IP, you have people, govs, nefarious groups scanning it. AWS will tell you the same as if you were hosting it locally, close up the ports, put it on a private network. Use a vpc and WAF in AWS' case.

I get scanned constantly. Every hour of every day dark forced attempt to penetrate our defences.

[-] [email protected] 49 points 8 hours ago

You contacted Amazon over a port scan?

[-] [email protected] 20 points 7 hours ago

I have 750 bots stuck in HTTP tarpits right now, and another 13 stuck in an SSH tarpit.

You can fight back! If we all fight back just a little bit, then mass-scanning and scraping becomes too expensive to do.

[-] [email protected] 3 points 7 hours ago
[-] [email protected] 15 points 7 hours ago

If I showed you my WAN-side firewall logs you'd have a panic attack. I have a /29 block and about 10 scans tap one IP or another every second. It's part of being on the internet.

Your domestic home router experiences the exact same thing. Every moment of every day.

Will you report every scan? Every Chinese IP? Every US IP? It's completely common place to have someone 'knock on the door'.

Get off IPv4 anyway and onto IPv6. Good luck to them finding you by chance in there.

[-] [email protected] 1 points 22 minutes ago

I ran a Tor relay on one of my spare servers for a while, and my god did that thing get port scanned. Even two years after I stopped hosting the relay, it was still getting pinged every 5-10 seconds (while my other servers tend to get pinged "only" once ever 20-30 seconds).

[-] [email protected] 9 points 7 hours ago

Remember to also report ssh login attempts and unauthorized wordpress access (even if wordpress isn't installed).

[-] [email protected] 7 points 7 hours ago

Also, all spam messages.

[-] [email protected] -2 points 7 hours ago

For SSH it will have to be attempted connections. Ain't no way I'm putting a forward facing SSH. I'll deal with any downtime that comes from not being able to access my server remotely

[-] [email protected] 8 points 7 hours ago

Haha, I get one of those every other day.

[-] [email protected] -1 points 7 hours ago

The sad reality of the Internet. Being the first for this new server feels like a "Welcome to the Internet, glad you are here" kind of message

[-] [email protected] 5 points 8 hours ago

I am reminded of a Richard Pryor skit in which he tells about a football player he knew who bit the fingers off of an opponent who was trying to gouge his eyes through his helmet. When Pryor asked him why he bit the guy's fingers off he said 'Everything outside the mask is his. Everything inside the mask is mine.'

this post was submitted on 09 Jul 2025
26 points (61.8% liked)

Selfhosted

49269 readers
746 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS