Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Abuse complaint : netscanout

Abuse complaint : netscanout

Scheduled Pinned Locked Moved Solved Support
7 Posts 3 Posters 1.7k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • timconsidineT Offline
    timconsidineT Offline
    timconsidine
    App Dev
    wrote on last edited by
    #1

    I'm hosting my Cloudron on Hetzner.
    I have not made any major changes in the last few days.
    Suddenly received abuse complaint from Hetzner saying that something is doing a portscan.
    Any ideas on :

    • what might be doing this?
    • how can I track down the app / process ?

    I have done netstat -anp but can't process the tonne of info generated.

    I need to make a response which will depend on what app is doing this.
    Info from Hetzner is poor (well maybe it's all they have) :

    > ##########################################################################
    > #               Netscan detected from host    88.99.143.85               #
    > ##########################################################################
    >
    > time                protocol src_ip src_port          dest_ip dest_port
    > ---------------------------------------------------------------------------
    > Thu May  4 15:11:55 2023 TCP    88.99.143.85 50686 =>         1.2.3.4 80
    > Thu May  4 15:11:58 2023 TCP    88.99.143.85 50686 =>         1.2.3.4 80
    > Thu May  4 15:11:51 2023 TCP    88.99.143.85 36084 =>         6.6.6.6 80
    > Thu May  4 15:11:49 2023 TCP    88.99.143.85 47388 =>       10.0.0.21 80
    .... and so on
    

    Indie app dev, scratching my itches, lover of Cloudron PaaS

    1 Reply Last reply
    1
    • BrutalBirdieB Offline
      BrutalBirdieB Offline
      BrutalBirdie
      Partner
      wrote on last edited by
      #2

      Using Meeting software a lot? Like Jitsi and stuff?

      Like my work? Consider donating a drink. Cheers!

      1 Reply Last reply
      1
      • timconsidineT Offline
        timconsidineT Offline
        timconsidine
        App Dev
        wrote on last edited by
        #3

        I have jitsi installed but I haven't used it in days.

        Trying to analyse ps -aux but it's 1200 lines, most of it is familiar, needle in haystack time.

        Indie app dev, scratching my itches, lover of Cloudron PaaS

        jdaviescoatesJ 1 Reply Last reply
        0
        • timconsidineT timconsidine

          I have jitsi installed but I haven't used it in days.

          Trying to analyse ps -aux but it's 1200 lines, most of it is familiar, needle in haystack time.

          jdaviescoatesJ Online
          jdaviescoatesJ Online
          jdaviescoates
          wrote on last edited by
          #4

          @timconsidine said in Abuse complaint : netscanout:

          I have jitsi installed but I haven't used it in days.

          Can people start meetings without having to login? If so, other people may be using it? 🤷

          I use Cloudron with Gandi & Hetzner

          timconsidineT 1 Reply Last reply
          0
          • jdaviescoatesJ jdaviescoates

            @timconsidine said in Abuse complaint : netscanout:

            I have jitsi installed but I haven't used it in days.

            Can people start meetings without having to login? If so, other people may be using it? 🤷

            timconsidineT Offline
            timconsidineT Offline
            timconsidine
            App Dev
            wrote on last edited by
            #5

            @jdaviescoates said in Abuse complaint : netscanout:

            Can people start meetings without having to login?

            That's a very good point.
            Thank you
            Let me check.

            Indie app dev, scratching my itches, lover of Cloudron PaaS

            1 Reply Last reply
            1
            • timconsidineT Offline
              timconsidineT Offline
              timconsidine
              App Dev
              wrote on last edited by
              #6

              The only other thing I can guess at is that I reinstalled SYNCTHING.
              (so I lied when I said I didn't change much 😊 )
              The new installation has a Global Discovery field set to default which I understand means that it will hunt out for friends to talk to.
              I've changed this to a specific value (the app address itself only) and disabled relaying.
              Seems still to work, but will test further.

              Indie app dev, scratching my itches, lover of Cloudron PaaS

              1 Reply Last reply
              3
              • timconsidineT Offline
                timconsidineT Offline
                timconsidine
                App Dev
                wrote on last edited by
                #7

                And I have deleted Jitsi for the moment.
                Not being used much currently.
                Will reinstall when I have time to get my head securing it.
                So will close this now.

                Indie app dev, scratching my itches, lover of Cloudron PaaS

                1 Reply Last reply
                1
                • timconsidineT timconsidine marked this topic as a question on
                • timconsidineT timconsidine has marked this topic as solved on

                Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                With your input, this post could be even better 💗

                Register Login
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • Bookmarks
                • Search