LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-11-2024, 04:00 AM   #1
Motaro
Member
 
Registered: Mar 2003
Location: USA, Florida
Distribution: slackware 12.1
Posts: 45

Rep: Reputation: 16
How are servers found on the internet that have no name registration?


I don't know, if people have this problem. Recently I saw a video of a person talking about it in youtube, and I found myself related to it. It seems that when you set up a server on the internet you very rapidly you start getting ssh dictionary attacks, even though you have a dynamic ip assignment and no name registration. I've tried in the past to do a network lookup for my subnet internet provider to see if I can see other computers, but it seems that the network provider blocks those messages.

So I'm curious how are hostile users of the internet finding servers so fast?

If anyone can bring some light to this problem will be appreciated.

Regards
 
Old 04-11-2024, 04:14 AM   #2
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,868

Rep: Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313Reputation: 7313
I guess that is just a more or less random try or scanning. Sometimes successful, sometimes not.
 
Old 04-11-2024, 04:53 AM   #3
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,313
Blog Entries: 3

Rep: Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723Reputation: 3723
Computing power has caught up with all that: It's quite affordable nowadays to fire up a pool of servers, AWS for example, and check each and ever port on every last IPv4 address in a matter of hours. The same can be said for the known IPv6 space (the ranges in actual use).

Here are two interesting links on that topic, one old, one new:

https://census2012.sourceforge.net/paper.html

https://www.shodan.io/


However, even before 'cloud' services hit the market, nefarious interests could pool compromised Windows servers and desktops for that task.
 
Old 04-11-2024, 12:30 PM   #4
jayjwa
Member
 
Registered: Jul 2003
Location: NY
Distribution: Slackware, Termux
Posts: 779

Rep: Reputation: 246Reputation: 246Reputation: 246
People use scanner tools that don't care about the name. They just scan entire netblocks for a port, say 22, then record that. This data is then passed on to another tool. nmap can do this. The ip6 address space is much quieter (at the moment).
 
Old 04-11-2024, 02:23 PM   #5
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,640

Rep: Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697Reputation: 2697
COMCAST (Xfinity) does network scanning on their subnets, and some threat actors do as well. My average time between getting a new device on the network and seeing dictionary attack activity averages right about ten minutes. (Some days as little as a minute or two, some days nearly half an hour.)

Never assume that name services can make you safe, they only make identifying nodes by name more convenient for PEOPLE. The hardware doesn't care, the criminals do not care.
 
Old 04-12-2024, 02:36 AM   #6
___
Member
 
Registered: Apr 2023
Posts: 141
Blog Entries: 1

Rep: Reputation: Disabled
Your PC probably has a private/non-routable/RFC1918 IP address, DHCP from ISP router. This might help:
https://security.stackexchange.com/q...et-through-nat
 
Old 04-12-2024, 03:12 PM   #7
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,987

Rep: Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628
Put wireshark on the wan side and you will see a constant attack stream.
 
1 members found this post helpful.
Old 04-12-2024, 08:53 PM   #8
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,329
Blog Entries: 28

Rep: Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144
I agree with the others. The most likely culprit is bad actors using random port scans.

If you have not done so, you may wish to install fail2ban.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] No package 'x11' found No package 'xext' found No package 'xdamage' found No package 'xfixes' found No package 'x11-xcb' found Jigsaw Linux From Scratch 14 02-23-2021 08:35 PM
Setting name servers on multiple servers centosfan Linux - Server 3 01-23-2008 03:43 PM
domain name registration and DHCP question ssfrstlstnm Debian 3 08-23-2005 10:21 PM
DNS name registration problems with static IP ccanning Linux - Networking 0 12-08-2004 03:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration