Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. Got my first script kiddy

Got my first script kiddy

Scheduled Pinned Locked Moved Selfhosted
selfhosted
51 Posts 27 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M [email protected]

    I don't have any open ports. I do not care if I did. Port scanning is not authorized traffic.

    I would love to see the support request from AWS for this.

    Here you go:

    Mandiant ASM scanners perform a variety of security-related data-gathering tasks, all intended to positively identify assets and their security posture. The gathered information is analyzed by our research team and proactively published to the owners of this information through our freemium product. No Collection task performed requires authorized access. It is intentionally designed to be light. While your IDS or WAF may have alerted on these scans, these are benign flags and are not indicative of malicious behavior.

    If you have further questions, or would like to opt-out, please reply to this message and you will be routed to the appropriate team.

    O This user is from outside of this forum
    O This user is from outside of this forum
    [email protected]
    wrote last edited by
    #7

    port scanning is not authorized traffic

    Hahahahahaha

    And?

    M C 2 Replies Last reply
    22
    • M [email protected]

      Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

      scrubbles@poptalk.scrubbles.techS This user is from outside of this forum
      scrubbles@poptalk.scrubbles.techS This user is from outside of this forum
      [email protected]
      wrote last edited by
      #8

      Uh sorry dude, but no this isn't a script kiddy, these are bots that scan every IP address every day for any open ports, it's a constant thing. If you have a public IP, you have people, govs, nefarious groups scanning it. AWS will tell you the same as if you were hosting it locally, close up the ports, put it on a private network. Use a vpc and WAF in AWS' case.

      I get scanned constantly. Every hour of every day dark forced attempt to penetrate our defences.

      M 1 Reply Last reply
      26
      • M [email protected]

        I don't have any open ports. I do not care if I did. Port scanning is not authorized traffic.

        I would love to see the support request from AWS for this.

        Here you go:

        Mandiant ASM scanners perform a variety of security-related data-gathering tasks, all intended to positively identify assets and their security posture. The gathered information is analyzed by our research team and proactively published to the owners of this information through our freemium product. No Collection task performed requires authorized access. It is intentionally designed to be light. While your IDS or WAF may have alerted on these scans, these are benign flags and are not indicative of malicious behavior.

        If you have further questions, or would like to opt-out, please reply to this message and you will be routed to the appropriate team.

        N This user is from outside of this forum
        N This user is from outside of this forum
        [email protected]
        wrote last edited by
        #9

        Port scanning is not authorized traffic.

        Lol what

        I think you should read the terms of your AWS contract. How do you think aws moves instances if not for agents gathering metrics?

        And this case is Mandiant, so you're fine.

        Are you sure you're ready for AWS?

        M 1 Reply Last reply
        7
        • N [email protected]

          Port scanning is not authorized traffic.

          Lol what

          I think you should read the terms of your AWS contract. How do you think aws moves instances if not for agents gathering metrics?

          And this case is Mandiant, so you're fine.

          Are you sure you're ready for AWS?

          M This user is from outside of this forum
          M This user is from outside of this forum
          [email protected]
          wrote last edited by
          #10

          Not on AWS

          1 Reply Last reply
          2
          • M [email protected]

            Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

            D This user is from outside of this forum
            D This user is from outside of this forum
            [email protected]
            wrote last edited by
            #11

            Remember to also report ssh login attempts and unauthorized wordpress access (even if wordpress isn't installed).

            M M 2 Replies Last reply
            6
            • M [email protected]

              Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

              R This user is from outside of this forum
              R This user is from outside of this forum
              [email protected]
              wrote last edited by
              #12

              Haha, I get one of those every other day.

              M 1 Reply Last reply
              5
              • M [email protected]

                Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

                schwim@lemmy.zipS This user is from outside of this forum
                schwim@lemmy.zipS This user is from outside of this forum
                [email protected]
                wrote last edited by
                #13

                It wasn't a script kiddy. It wasn't even a human. You are going to be a very busy individual if you decide to report every port scan you find.

                M 1 Reply Last reply
                45
                • scrubbles@poptalk.scrubbles.techS [email protected]

                  Uh sorry dude, but no this isn't a script kiddy, these are bots that scan every IP address every day for any open ports, it's a constant thing. If you have a public IP, you have people, govs, nefarious groups scanning it. AWS will tell you the same as if you were hosting it locally, close up the ports, put it on a private network. Use a vpc and WAF in AWS' case.

                  I get scanned constantly. Every hour of every day dark forced attempt to penetrate our defences.

                  M This user is from outside of this forum
                  M This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #14

                  Not on AWS and yes I know I can't stop port scanning and bad traffic is a thing. Doesn't stop me from filling out the form. I think to piss off you and the other commenters, I'll write a script to auto fill out AWS abuse forms. Also script kiddy or bot, all the same to me, their hosting provider is getting a message from me

                  irmadlad@lemmy.worldI scrubbles@poptalk.scrubbles.techS remotelove@lemmy.caR R I 6 Replies Last reply
                  3
                  • O [email protected]

                    port scanning is not authorized traffic

                    Hahahahahaha

                    And?

                    M This user is from outside of this forum
                    M This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #15

                    And abuse forms get filled out

                    S 1 Reply Last reply
                    2
                    • schwim@lemmy.zipS [email protected]

                      It wasn't a script kiddy. It wasn't even a human. You are going to be a very busy individual if you decide to report every port scan you find.

                      M This user is from outside of this forum
                      M This user is from outside of this forum
                      [email protected]
                      wrote last edited by
                      #16

                      That's what automation is for

                      S 1 Reply Last reply
                      1
                      • D [email protected]

                        Remember to also report ssh login attempts and unauthorized wordpress access (even if wordpress isn't installed).

                        M This user is from outside of this forum
                        M This user is from outside of this forum
                        [email protected]
                        wrote last edited by
                        #17

                        Also, all spam messages.

                        1 Reply Last reply
                        4
                        • R [email protected]

                          Haha, I get one of those every other day.

                          M This user is from outside of this forum
                          M This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #18

                          The sad reality of the Internet. Being the first for this new server feels like a "Welcome to the Internet, glad you are here" kind of message

                          1 Reply Last reply
                          1
                          • D [email protected]

                            Remember to also report ssh login attempts and unauthorized wordpress access (even if wordpress isn't installed).

                            M This user is from outside of this forum
                            M This user is from outside of this forum
                            [email protected]
                            wrote last edited by
                            #19

                            For SSH it will have to be attempted connections. Ain't no way I'm putting a forward facing SSH. I'll deal with any downtime that comes from not being able to access my server remotely

                            1 Reply Last reply
                            0
                            • M [email protected]

                              Not on AWS and yes I know I can't stop port scanning and bad traffic is a thing. Doesn't stop me from filling out the form. I think to piss off you and the other commenters, I'll write a script to auto fill out AWS abuse forms. Also script kiddy or bot, all the same to me, their hosting provider is getting a message from me

                              irmadlad@lemmy.worldI This user is from outside of this forum
                              irmadlad@lemmy.worldI This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #20

                              Not on AWS and yes I know I can’t stop port scanning and bad traffic is a thing. Doesn’t stop me from filling out the form.

                              On occasion, if they end up in recidive, I'll report them to AbuseIPdb. If I did it for all attempts, I'd be as busy as a squirrel in a nut factory, because the bots are thick out in the ether. Like every minute of the day they're out there throwing rocks at the castle wall. I had to start logrotating because logs were getting so big it was difficult to review and audit. Every so once in a while, they'll break out the trebuchet and lob something significant, but I've had no breaches to date.

                              My servers are single user only, so buttoning things down is a little less complicated for me.

                              1 Reply Last reply
                              0
                              • M [email protected]

                                Not on AWS and yes I know I can't stop port scanning and bad traffic is a thing. Doesn't stop me from filling out the form. I think to piss off you and the other commenters, I'll write a script to auto fill out AWS abuse forms. Also script kiddy or bot, all the same to me, their hosting provider is getting a message from me

                                scrubbles@poptalk.scrubbles.techS This user is from outside of this forum
                                scrubbles@poptalk.scrubbles.techS This user is from outside of this forum
                                [email protected]
                                wrote last edited by [email protected]
                                #21

                                I mean go for it? They literally can't do anything, you might as well complain that fire is hot though. It's part of being in the Internet. They provide safety gloves, via VPCs and firewalls, but if you choose not to use them then.. yeah I mean youre probably gonna get burned

                                1 Reply Last reply
                                3
                                • M [email protected]

                                  I don't have any open ports. I do not care if I did. Port scanning is not authorized traffic.

                                  I would love to see the support request from AWS for this.

                                  Here you go:

                                  Mandiant ASM scanners perform a variety of security-related data-gathering tasks, all intended to positively identify assets and their security posture. The gathered information is analyzed by our research team and proactively published to the owners of this information through our freemium product. No Collection task performed requires authorized access. It is intentionally designed to be light. While your IDS or WAF may have alerted on these scans, these are benign flags and are not indicative of malicious behavior.

                                  If you have further questions, or would like to opt-out, please reply to this message and you will be routed to the appropriate team.

                                  R This user is from outside of this forum
                                  R This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by
                                  #22

                                  In other words their response was “hey dumbass here’s what happened, now move along”. They didn’t do anything except school you.

                                  M 1 Reply Last reply
                                  10
                                  • M [email protected]

                                    Not on AWS and yes I know I can't stop port scanning and bad traffic is a thing. Doesn't stop me from filling out the form. I think to piss off you and the other commenters, I'll write a script to auto fill out AWS abuse forms. Also script kiddy or bot, all the same to me, their hosting provider is getting a message from me

                                    remotelove@lemmy.caR This user is from outside of this forum
                                    remotelove@lemmy.caR This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #23

                                    Good luck with that, I suppose. Botnets can have thousands, if not hundreds of thousands of infected hosts that will endlessly scan everything on the interwebs. Many of those infected hosts are behind NAT's and your abuse form would be the equivalent of reporting an entire region for a single scan.

                                    But hey! Change the world, amirite?

                                    irmadlad@lemmy.worldI 1 Reply Last reply
                                    7
                                    • M [email protected]

                                      Nice big old port scan. Brand new server too. Just a few days old so there is nothing to find. Don't worry I contacted AWS. Stay safe out there.

                                      C This user is from outside of this forum
                                      C This user is from outside of this forum
                                      [email protected]
                                      wrote last edited by
                                      #24

                                      If I showed you my WAN-side firewall logs you'd have a panic attack. I have a /29 block and about 10 scans tap one IP or another every second. It's part of being on the internet.

                                      Your domestic home router experiences the exact same thing. Every moment of every day.

                                      Will you report every scan? Every Chinese IP? Every US IP? It's completely common place to have someone 'knock on the door'.

                                      Get off IPv4 anyway and onto IPv6. Good luck to them finding you by chance in there.

                                      C 1 Reply Last reply
                                      7
                                      • remotelove@lemmy.caR [email protected]

                                        Good luck with that, I suppose. Botnets can have thousands, if not hundreds of thousands of infected hosts that will endlessly scan everything on the interwebs. Many of those infected hosts are behind NAT's and your abuse form would be the equivalent of reporting an entire region for a single scan.

                                        But hey! Change the world, amirite?

                                        irmadlad@lemmy.worldI This user is from outside of this forum
                                        irmadlad@lemmy.worldI This user is from outside of this forum
                                        [email protected]
                                        wrote last edited by
                                        #25

                                        Meh. I know everyone is giving OP the piss, but I used to fret about this type of stuff long time ago. LOL That became a job. Then I learned a little more and realized I wasn't being targeted specifically by some hooded specter in a dimly lit basement emphatically announcing 'I'm in!', but that these were bots. Sophisticated bots tho, I'll give them that.

                                        remotelove@lemmy.caR 1 Reply Last reply
                                        0
                                        • O [email protected]

                                          port scanning is not authorized traffic

                                          Hahahahahaha

                                          And?

                                          C This user is from outside of this forum
                                          C This user is from outside of this forum
                                          [email protected]
                                          wrote last edited by
                                          #26

                                          I think they have a LOT to learn about how the internet 'works' as well as how the internet works.

                                          irmadlad@lemmy.worldI 1 Reply Last reply
                                          14
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups