LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-21-2018, 08:25 AM   #1
tfstfs
LQ Newbie
 
Registered: Apr 2018
Posts: 2

Rep: Reputation: Disabled
Intensive portscans from all over the world


From time to time I am getting firewall notifications about portscans on the server. Sometimes arrive 5-20 messages per day, sometimes there are no messages for weeks and months.

Since yesterday such messages started to arrive every 3-5 minutes. Portscans from all over the world - USA, Germany, Italy, Sweden, Japan, Australia, Saudi Arabia, Ecuador etc, etc. IP addresses don't reteat.

All meessages contain the same port numbers; 2004, 7001, 8080. Is anyone experiencing something like this? What is the purpose tu run the same port scans from all ovewr the world?

Thanks.

============================

Code:
Time:    Sat Apr 21 13:48:54 2018 +0100
IP:      165.227.193.20 (US/United States/-)
Hits:    11
Blocked: Temporary Block for 3600 seconds [PS_LIMIT]

Sample of block hits:
Apr 21 13:48:32 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54341 DF PROTO=TCP SPT=45230 DPT=7001 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:33 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54342 DF PROTO=TCP SPT=45230 DPT=7001 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:35 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54343 DF PROTO=TCP SPT=45230 DPT=7001 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:37 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=42335 DF PROTO=TCP SPT=57062 DPT=2004 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:38 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=42336 DF PROTO=TCP SPT=57062 DPT=2004 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:40 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=42337 DF PROTO=TCP SPT=57062 DPT=2004 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:43 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=36264 DF PROTO=TCP SPT=46744 DPT=8080 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:44 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=36265 DF PROTO=TCP SPT=46744 DPT=8080 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:46 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:1c:e6:c7:52:07:40:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=36266 DF PROTO=TCP SPT=46744 DPT=8080 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:48 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:10:bd:18:e5:ff:80:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54269 DF PROTO=TCP SPT=48520 DPT=8080 WINDOW=29200 RES=0x00 SYN URGP=0 
Apr 21 13:48:49 srv2 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=08:60:6e:69:79:35:10:bd:18:e5:ff:80:08:00 SRC=165.227.193.20 DST=XXX.XXX.XXX.XXX LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54270 DF PROTO=TCP SPT=48520 DPT=8080 WINDOW=29200 RES=0x00 SYN URGP=0
 
Old 04-21-2018, 03:46 PM   #2
coralfang
Member
 
Registered: Nov 2010
Location: Bristol, UK
Distribution: Slackware, FreeBSD
Posts: 836
Blog Entries: 3

Rep: Reputation: 297Reputation: 297Reputation: 297
Sounds like an automated botnet scanning for a service running on those open ports.

I just searched and found this article on BleepingComputer, posted yesterday (20th april); which goes on to mention a particular botnet is actively scanning the ports you mentioned; 2004, 7001, and 8080.

https://www.bleepingcomputer.com/new...vulnerability/


I would assume you're getting scanned by this.
Quote:
A botnet made up of servers and smart devices has begun the mass exploitation of a severe Drupal CMS vulnerability and is using already compromised systems to infect new machines, in a worm-like behavior.

The botnet is exploiting the CVE-2018-7600 vulnerability —also known as Drupalgeddon 2— to access a specific URL and gain the ability to execute commands on a server running the Drupal CMS.
Quote:
80: Weblogic, Wordpress, Drupal, WebDav, ClipBucket
2004: Webuzo
7001: Weblogic
8080: Wordpress, WebDav, DasanNetwork Solution
 
Old 04-21-2018, 04:13 PM   #3
tfstfs
LQ Newbie
 
Registered: Apr 2018
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thank you very much for your answer.
Yes, it looks like a botnet. A few hours ago all portscans stopped and I am not getting a single firewall notification anymore.
 
Old 04-21-2018, 09:07 PM   #4
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,324
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
Remote port scans are a fact of life on the internet and have been for a long long time. They are one of the reasons firewalls are a good thing.
 
Old 04-22-2018, 06:10 PM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Port-scans are so commonplace that they're not really interesting enough to log. What's troublesome is what comes next.

This is why I protect my systems – as I describe in my blog here – with OpenVPN, using one-of-a-kind digital certificates and tls-auth. According to anything that anyone can see from the outside, the only "open ports" are 80 and 443. OpenVPN itself cannot be detected even if you suspect that it is there ... somewhere.

Unless you possess a valid credential that was issued only to you and that hasn't been revoked, "there's nothing there." (Even so, "further, inner, rings of protection" await those who are allowed to pass.)

Number of unauthorized access attempts: Zero.

Last edited by sundialsvcs; 04-22-2018 at 06:14 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Cat command I/O intensive question. neoanomally Linux - Newbie 7 08-20-2012 09:00 PM
Firewall crashes - Then massive portscans micxz Linux - Security 8 07-23-2009 12:18 AM
Data-Intensive Computations itnaa Linux - Hardware 4 05-25-2008 10:58 PM
FC3 seems very CPU-intensive deadmilkman Fedora 6 12-30-2004 05:04 PM
Snort detects loads of portscans from.. uh.. myself? sh1ft Linux - Security 1 09-01-2004 08:25 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration