Forum Moderators: phranque

Message Too Old, No Replies

Am i being scanned / monitored?

Constant incomming requests without a server response

         

akwexavante

1:05 pm on Oct 25, 2019 (gmt 0)

10+ Year Member




Leap openSUSE
Apache2
ports 80 & 443

I'm getting constant incomming connection requests from italy and korea on port 80 wich are redirected to 443 over and over but my server isn't responding. There are no entries in my server access / error logfiles for the ip address.

My router is accepting these incomming requests and forwarding them to my server constantly but there are no corresponding outward connection requests from my server which i would normally see.

When i block the offending ip address range within 10 to 15 seconds the same activity starts again from a different ip address range and so on.

What is this activity and should i be worrying about it? Or should i just ignore it?

TorontoBoy

2:26 pm on Oct 25, 2019 (gmt 0)

5+ Year Member Top Contributors Of The Month



Can you post an IP range, user agent name? Is it hitting a web site or just doing a probe? Are you monitoring your raw access log?

lucy24

5:58 pm on Oct 25, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



requests from italy and korea on port 80 wich are redirected to 443 over and over but my server isn't responding
This is unclear. Your server sends out the redirect response: that's one part. But are your unwanted visitors following up on the redirect? Some robots receive the http-to-https redirect response and never make the follow-up request. (Yay!)

When i block the offending ip address range within 10 to 15 seconds the same activity starts again from a different ip address range
You'll need to find some other aspect of the request to block, then. Take a closer look and see if there are any distinctive headers, or--if the robot isn't very bright--a consistent user-agent. But if your server isn't sending out content (“server isn’t responding”), what difference does it make? You can’t stop requests from being made; you can only stop the server from giving them what they want.

akwexavante

6:26 pm on Oct 28, 2019 (gmt 0)

10+ Year Member



My server is on local ip address 10.1.1.20

None of my servers logfiles have any entries for the ip address 13.229.72.179, plenty of other "normal and expected" entries though ( On this occasion the IP address is an Amazon IP Address by chance ) but over the last week the IP addresses have been from Korea, Italy, Ukraine and others. For hour after hour after hour for at least the last 10 days or so, continuous. The web server hosts just 4 websites and all are performing as i would normally expect them to. For the last 8 days the IP address 54.39.173.86 has been doing the same thing over and over by the second continuously, there are no entries in my servers logfiles for this IP address either.


Log entries from my Draytek Router: (17 seconds)

150 2019-10-28 17:51:06 Oct 28 17:51:04 WORKSHOP Open port: 13.229.72.179:65327 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:06 Oct 28 17:51:04 WORKSHOP Open port: 13.229.72.179:64574 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:06 Oct 28 17:51:04 WORKSHOP Open port: 13.229.72.179:40244 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:08 Oct 28 17:51:06 WORKSHOP Open port: 13.229.72.179:50911 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:10 Oct 28 17:51:08 WORKSHOP Open port: 13.229.72.179:52210 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:10 Oct 28 17:51:08 WORKSHOP Open port: 13.229.72.179:43366 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:10 Oct 28 17:51:08 WORKSHOP Open port: 13.229.72.179:64208 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:11 Oct 28 17:51:09 WORKSHOP Local User (MAC=00-24-1D-DD-94-EA): 10.1.1.20:52580 -> 195.135.221.140:80 (TCP)Web
150 2019-10-28 17:51:11 Oct 28 17:51:09 WORKSHOP Local User: 195.135.221.140:80 -> 10.1.1.20:52580 (TCP) close connection
150 2019-10-28 17:51:12 Oct 28 17:51:10 WORKSHOP Open port: 13.229.72.179:51662 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:12 Oct 28 17:51:10 WORKSHOP Open port: 13.229.72.179:44264 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:12 Oct 28 17:51:11 WORKSHOP Open port: 13.229.72.179:61700 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:13 Oct 28 17:51:11 WORKSHOP Open port: 13.229.72.179:57653 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:13 Oct 28 17:51:11 WORKSHOP Open port: 13.229.72.179:61587 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:13 Oct 28 17:51:11 WORKSHOP Open port: 13.229.72.179:42840 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:14 Oct 28 17:51:12 WORKSHOP Open port: 13.229.72.179:54744 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:14 Oct 28 17:51:12 WORKSHOP Open port: 13.229.72.179:51551 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:14 Oct 28 17:51:12 WORKSHOP Open port: 13.229.72.179:65476 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:15 Oct 28 17:51:13 WORKSHOP Open port: 13.229.72.179:41022 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:15 Oct 28 17:51:13 WORKSHOP Open port: 13.229.72.179:47606 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:15 Oct 28 17:51:13 WORKSHOP Open port: 13.229.72.179:56031 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:15 Oct 28 17:51:13 WORKSHOP Open port: 13.229.72.179:50751 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:16 Oct 28 17:51:14 WORKSHOP Open port: 13.229.72.179:36940 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:17 Oct 28 17:51:15 WORKSHOP Open port: 13.229.72.179:33632 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:17 Oct 28 17:51:15 WORKSHOP Open port: 13.229.72.179:40999 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:18 Oct 28 17:51:16 WORKSHOP Open port: 13.229.72.179:62715 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:18 Oct 28 17:51:16 WORKSHOP Open port: 13.229.72.179:49994 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:19 Oct 28 17:51:17 WORKSHOP Open port: 13.229.72.179:45310 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:20 Oct 28 17:51:18 WORKSHOP Open port: 13.229.72.179:38335 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:22 Oct 28 17:51:20 WORKSHOP Open port: 13.229.72.179:44509 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:22 Oct 28 17:51:20 WORKSHOP Open port: 13.229.72.179:41479 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:22 Oct 28 17:51:20 WORKSHOP Open port: 13.229.72.179:45221 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:22 Oct 28 17:51:20 WORKSHOP Open port: 13.229.72.179:35024 -> 10.1.1.20:80 (TCP) Web
150 2019-10-28 17:51:23 Oct 28 17:51:21 WORKSHOP Open port: 13.229.72.179:45488 -> 10.1.1.20:443 (TCP)
150 2019-10-28 17:51:23 Oct 28 17:51:21 WORKSHOP Open port: 13.229.72.179:62222 -> 10.1.1.20:443 (TCP)

The Draytek router isn't passing through an unusual amount of data either inwardly (Down) or outwardly (Up)

Just curious about what's going on here, trying to understand what this is all about and if i should be doing anything about it or not. Just cannot grasp what these incomming requests are, what's going on. If theres nothing to do and nothing to be concerned about then that's good. But not knowing or understanding what this activity is, i'd like to know and establish if i should be doing anything about it. It's been 10 days now, relentless inbound activity to my server but can't work out why.

akwexavante

9:39 am on Nov 7, 2019 (gmt 0)

10+ Year Member



The problem has now come to an end, my router is no longer recording 10's of thousands of requests to open ports 80 & 433 to my server!