Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. Got my first script kiddy

Got my first script kiddy

Scheduled Pinned Locked Moved Selfhosted
selfhosted
51 Posts 27 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M [email protected]

    Dude there is a weird disconnect going on in the comments. Yes bots are thing, yes services are abused, yes not everyone plays nice on the Internet, yes you can't control what traffic comes in. I know I'm going to be seeing more this and yes I'm obviously not going to be responding to every one of them.

    It was my brand new server's first and I felt like celebrating the event by filling out the AWS abuse form. It was literally copy and paste.

    Also, I'm not fussed about what ever services they are running. I didn't ask for it or want it. I told them as much and I going to leave it at that.

    No one got schooled. There is nothing wrong with telling someone who shows up at your business to please don't come back. Y'all need to chill.

    Well this whole thing was fun but I'm going to get on with my day

    N This user is from outside of this forum
    N This user is from outside of this forum
    [email protected]
    wrote last edited by
    #32

    I don't think anyone here disagrees that port scanning is bad, nor that you even filed an aws ticket. And congrats on your live service.

    But your answers to comments are weird, like this is not only your first server or vps experience with a public interface, but your first time exposing anything to the public web. And even if that's true, there's a first time for everyone.

    But man, doubling down and insisting that "port scanning is unauthorized traffic" betrays a certain naivete about how tcpip works.

    What you are seeing is not only normal, but AWS can't do anything about it because that's how IP source and destination sockets work.

    1 Reply Last reply
    13
    • M [email protected]

      Yes. Don't port scan my shit.

      A This user is from outside of this forum
      A This user is from outside of this forum
      [email protected]
      wrote last edited by
      #33

      "Good luck with that."

      I realize you're inexperienced and excited, but this is truly no big deal. Port scans are quite common and aren't even always malicious. You can use nmap to scan systems yourself - just to see what's out there or to test if your firewalls are woking, etc.

      qt0x40490fdb@lemmy.mlQ 1 Reply Last reply
      2
      • remotelove@lemmy.caR [email protected]

        My general attitude is similar to yours. Let OP figure out that the reporting and blocking is basically just creating more noise that has to gets filtered out and bot supply is basically infinite.

        "It's a learning experience."

        scrubbles@poptalk.scrubbles.techS This user is from outside of this forum
        scrubbles@poptalk.scrubbles.techS This user is from outside of this forum
        [email protected]
        wrote last edited by
        #34

        Yeah with Amazon's sheer size this has definitely been done before, curious what limits op is going to hit. My guess is they have a quota for submissions, and they'll be banned from submitting tickets.

        1 Reply Last reply
        1
        • C [email protected]

          I think they have a LOT to learn about how the internet 'works' as well as how the internet works.

          irmadlad@lemmy.worldI This user is from outside of this forum
          irmadlad@lemmy.worldI This user is from outside of this forum
          [email protected]
          wrote last edited by [email protected]
          #35

          Thing is, for the average consumer of the internet, they have no real concept what's going on behind the webpage with the fancy graphics they happen to be looking at. When I try to explain to them that bots comprise conservatively 40-50% of all internet traffic which is about ~2 zettabytes per 24 hour period, they still don't get it. And really, they don't have to, that's the job of sysadmin. It's still pretty mind blowing.

          1 Reply Last reply
          2
          • M [email protected]

            Not on AWS and yes I know I can't stop port scanning and bad traffic is a thing. Doesn't stop me from filling out the form. I think to piss off you and the other commenters, I'll write a script to auto fill out AWS abuse forms. Also script kiddy or bot, all the same to me, their hosting provider is getting a message from me

            I This user is from outside of this forum
            I This user is from outside of this forum
            [email protected]
            wrote last edited by
            #36

            Port scanning isn't abuse but automatically filing frivilous abuse reports is.

            1 Reply Last reply
            27
            • M [email protected]

              Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

              C This user is from outside of this forum
              C This user is from outside of this forum
              [email protected]
              wrote last edited by
              #37

              Switch to IPv6 only and the port scans will go away. The address space is so big that port scanning is difficult, so the usual bots don't bother.

              kairubyte@lemmy.dbzer0.comK 1 Reply Last reply
              5
              • A [email protected]

                "Good luck with that."

                I realize you're inexperienced and excited, but this is truly no big deal. Port scans are quite common and aren't even always malicious. You can use nmap to scan systems yourself - just to see what's out there or to test if your firewalls are woking, etc.

                qt0x40490fdb@lemmy.mlQ This user is from outside of this forum
                qt0x40490fdb@lemmy.mlQ This user is from outside of this forum
                [email protected]
                wrote last edited by
                #38

                And the first time I used nmap on my college network, a professor called up the help desk to report that he had been port scanned.

                Then my freind at the help desk told me not to run nmap again and to wait until after dark to pull all the reel to reel tapes out of the dumpster….

                1 Reply Last reply
                0
                • C [email protected]

                  Switch to IPv6 only and the port scans will go away. The address space is so big that port scanning is difficult, so the usual bots don't bother.

                  kairubyte@lemmy.dbzer0.comK This user is from outside of this forum
                  kairubyte@lemmy.dbzer0.comK This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #39

                  Sure but there are just some things you can’t run over ipv6

                  C 1 Reply Last reply
                  0
                  • C [email protected]

                    If I showed you my WAN-side firewall logs you'd have a panic attack. I have a /29 block and about 10 scans tap one IP or another every second. It's part of being on the internet.

                    Your domestic home router experiences the exact same thing. Every moment of every day.

                    Will you report every scan? Every Chinese IP? Every US IP? It's completely common place to have someone 'knock on the door'.

                    Get off IPv4 anyway and onto IPv6. Good luck to them finding you by chance in there.

                    C This user is from outside of this forum
                    C This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #40

                    I ran a Tor relay on one of my spare servers for a while, and my god did that thing get port scanned. Even two years after I stopped hosting the relay, it was still getting pinged every 5-10 seconds (while my other servers tend to get pinged "only" once ever 20-30 seconds).

                    1 Reply Last reply
                    1
                    • kairubyte@lemmy.dbzer0.comK [email protected]

                      Sure but there are just some things you can’t run over ipv6

                      C This user is from outside of this forum
                      C This user is from outside of this forum
                      [email protected]
                      wrote last edited by
                      #41

                      Such as?

                      C 1 Reply Last reply
                      0
                      • M [email protected]

                        Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

                        T This user is from outside of this forum
                        T This user is from outside of this forum
                        [email protected]
                        wrote last edited by
                        #42

                        Trying to learn here, are these SSH login attempts on the root user? If not, is it just the firewall logs?

                        1 Reply Last reply
                        4
                        • C [email protected]

                          Such as?

                          C This user is from outside of this forum
                          C This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #43

                          Some game servers, some ISPs don't provide IPv6 for (some of) their customers.

                          S C 2 Replies Last reply
                          1
                          • C [email protected]

                            Some game servers, some ISPs don't provide IPv6 for (some of) their customers.

                            S This user is from outside of this forum
                            S This user is from outside of this forum
                            [email protected]
                            wrote last edited by
                            #44

                            Yup, we don't have IPv6, so we'd need a VPN or something to do that.

                            1 Reply Last reply
                            0
                            • M [email protected]

                              That's what automation is for

                              S This user is from outside of this forum
                              S This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #45

                              Or just close off the most common vectors, such as disabling root ssh login, doing key-only SSH auth, and block traffic from regions of the world you don't need to support.

                              W 1 Reply Last reply
                              8
                              • C [email protected]

                                Some game servers, some ISPs don't provide IPv6 for (some of) their customers.

                                C This user is from outside of this forum
                                C This user is from outside of this forum
                                [email protected]
                                wrote last edited by
                                #46

                                Ah game servers yes that's fair. I found that with Astroneer. If the ISP doesn't provide V6 though it's time to switch ISPs.

                                Majority of traffic to Google is now V6 in most countries. Globally it's still just under 50%. https://www.google.com/intl/en/ipv6/statistics.html

                                W 1 Reply Last reply
                                0
                                • S [email protected]

                                  Or just close off the most common vectors, such as disabling root ssh login, doing key-only SSH auth, and block traffic from regions of the world you don't need to support.

                                  W This user is from outside of this forum
                                  W This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by
                                  #47

                                  I got a huge reduction in random login attempts when I changed my ssh port away from the default.

                                  (Of course I also have actual security measures like log in by key only)

                                  1 Reply Last reply
                                  3
                                  • C [email protected]

                                    Ah game servers yes that's fair. I found that with Astroneer. If the ISP doesn't provide V6 though it's time to switch ISPs.

                                    Majority of traffic to Google is now V6 in most countries. Globally it's still just under 50%. https://www.google.com/intl/en/ipv6/statistics.html

                                    W This user is from outside of this forum
                                    W This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #48

                                    If the ISP doesn't provide V6 though it's time to switch ISPs.

                                    cries in USA

                                    C 1 Reply Last reply
                                    0
                                    • M [email protected]

                                      Not on AWS and yes I know I can't stop port scanning and bad traffic is a thing. Doesn't stop me from filling out the form. I think to piss off you and the other commenters, I'll write a script to auto fill out AWS abuse forms. Also script kiddy or bot, all the same to me, their hosting provider is getting a message from me

                                      R This user is from outside of this forum
                                      R This user is from outside of this forum
                                      [email protected]
                                      wrote last edited by [email protected]
                                      #49

                                      I'll write a script to auto fill out AWS abuse forms

                                      Sounds like you are the script kiddie here

                                      1 Reply Last reply
                                      2
                                      • W [email protected]

                                        If the ISP doesn't provide V6 though it's time to switch ISPs.

                                        cries in USA

                                        C This user is from outside of this forum
                                        C This user is from outside of this forum
                                        [email protected]
                                        wrote last edited by
                                        #50

                                        You could always get a tunneled V6 line but it's a lot of hassle for something you should have by default.

                                        Us europoors may not have golden toilet seats and medical insurance, or V8 Chevvies, or American Size Mayonnaise, but we have our 2a02:7892:1234:::/64!!!!!

                                        Monopolistic control of buildings by one ISP is illegal in most Euro countries 😄

                                        1 Reply Last reply
                                        0
                                        • M [email protected]

                                          Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

                                          U This user is from outside of this forum
                                          U This user is from outside of this forum
                                          [email protected]
                                          wrote last edited by [email protected]
                                          #51

                                          I think a lot of peope understandably misunderstand this post because it doesn't really explain the situation. After reading OP's comments I gather that OP put a new server online (not on AWS) and was immediately port scanned by a host that is on AWS. Since OP did not consent to being port scanned, they filled out an abuse complaint with AWS, the hoster the scan came from, out of principle, knowing that it probably won't do much. Which is totally fine if that is how you want to spend your time.

                                          I think what most commenters thought is that OP was hosting with AWS and complained to them that someone else scanned their server. This does not seem to be the case.

                                          1 Reply Last reply
                                          3
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups