Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Abuse complaint : netscanout

Abuse complaint : netscanout

Scheduled Pinned Locked Moved Solved Support
7 Posts 3 Posters 839 Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • timconsidineT Offline
      timconsidineT Offline
      timconsidine
      App Dev
      wrote on last edited by
      #1

      I'm hosting my Cloudron on Hetzner.
      I have not made any major changes in the last few days.
      Suddenly received abuse complaint from Hetzner saying that something is doing a portscan.
      Any ideas on :

      • what might be doing this?
      • how can I track down the app / process ?

      I have done netstat -anp but can't process the tonne of info generated.

      I need to make a response which will depend on what app is doing this.
      Info from Hetzner is poor (well maybe it's all they have) :

      > ##########################################################################
      > #               Netscan detected from host    88.99.143.85               #
      > ##########################################################################
      >
      > time                protocol src_ip src_port          dest_ip dest_port
      > ---------------------------------------------------------------------------
      > Thu May  4 15:11:55 2023 TCP    88.99.143.85 50686 =>         1.2.3.4 80
      > Thu May  4 15:11:58 2023 TCP    88.99.143.85 50686 =>         1.2.3.4 80
      > Thu May  4 15:11:51 2023 TCP    88.99.143.85 36084 =>         6.6.6.6 80
      > Thu May  4 15:11:49 2023 TCP    88.99.143.85 47388 =>       10.0.0.21 80
      .... and so on
      
      1 Reply Last reply
      1
      • BrutalBirdieB Offline
        BrutalBirdieB Offline
        BrutalBirdie
        Partner
        wrote on last edited by
        #2

        Using Meeting software a lot? Like Jitsi and stuff?

        Like my work? Consider donating a drink. Cheers!

        1 Reply Last reply
        1
        • timconsidineT Offline
          timconsidineT Offline
          timconsidine
          App Dev
          wrote on last edited by
          #3

          I have jitsi installed but I haven't used it in days.

          Trying to analyse ps -aux but it's 1200 lines, most of it is familiar, needle in haystack time.

          jdaviescoatesJ 1 Reply Last reply
          0
          • timconsidineT timconsidine

            I have jitsi installed but I haven't used it in days.

            Trying to analyse ps -aux but it's 1200 lines, most of it is familiar, needle in haystack time.

            jdaviescoatesJ Offline
            jdaviescoatesJ Offline
            jdaviescoates
            wrote on last edited by
            #4

            @timconsidine said in Abuse complaint : netscanout:

            I have jitsi installed but I haven't used it in days.

            Can people start meetings without having to login? If so, other people may be using it? 🤷

            I use Cloudron with Gandi & Hetzner

            timconsidineT 1 Reply Last reply
            0
            • jdaviescoatesJ jdaviescoates

              @timconsidine said in Abuse complaint : netscanout:

              I have jitsi installed but I haven't used it in days.

              Can people start meetings without having to login? If so, other people may be using it? 🤷

              timconsidineT Offline
              timconsidineT Offline
              timconsidine
              App Dev
              wrote on last edited by
              #5

              @jdaviescoates said in Abuse complaint : netscanout:

              Can people start meetings without having to login?

              That's a very good point.
              Thank you
              Let me check.

              1 Reply Last reply
              1
              • timconsidineT Offline
                timconsidineT Offline
                timconsidine
                App Dev
                wrote on last edited by
                #6

                The only other thing I can guess at is that I reinstalled SYNCTHING.
                (so I lied when I said I didn't change much 😊 )
                The new installation has a Global Discovery field set to default which I understand means that it will hunt out for friends to talk to.
                I've changed this to a specific value (the app address itself only) and disabled relaying.
                Seems still to work, but will test further.

                1 Reply Last reply
                3
                • timconsidineT Offline
                  timconsidineT Offline
                  timconsidine
                  App Dev
                  wrote on last edited by
                  #7

                  And I have deleted Jitsi for the moment.
                  Not being used much currently.
                  Will reinstall when I have time to get my head securing it.
                  So will close this now.

                  1 Reply Last reply
                  1
                  • timconsidineT timconsidine marked this topic as a question on
                  • timconsidineT timconsidine has marked this topic as solved on
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                    • Login

                    • Don't have an account? Register

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • Bookmarks
                    • Search