Why you are scanned so soon
-
I found it interesting that if you get a certificate for your web site you are publicly announced and apparently scanned immediately by the bad guys.
https://isc.sans.edu/diary/Survival+time+for+web+sites/30170/?is=55349e6df1ae7d0eb1f5f3ef0a11b2b29cccb62b3a13d647441b48fa18c8f5d6
-
@AndyRH said in Why you are scanned so soon:
https://isc.sans.edu/diary/Survival+time+for+web+sites/30170/?is=55349e6df1ae7d0eb1f5f3ef0a11b2b29cccb62b3a13d647441b48fa18c8f5d6
Yeah that is interesting - but not like wouldn't be unheard of. Any data like this would be valuable to the bad guys. I find it funny that the first scan was from DO.. Good thing I block all their known IPs, along with all the other scanners that I know about..
As the article points out - such info will be made use of, while sure could be used for good.. All good things can be used for bad as well, when the genie is let out of the bottle on any new tech, its bound to be used for bad..
There is no possible way any actual legit user would be coming from any of those scanner IPs, etc. There is little reason not to block them, etc.. While they think they might be doing good, and maybe in the long run maybe the good can out weigh the bad.. But for the couple of services I provide to my users, those scanner services aren't doing me any favors so I block them all, shoden, stretchoid and shadowserver just a few of them off the top my head.
The best part of that article is the mention of making sure your service is secure before exposure to the public internet.. That should be more stressed to be honest..
And only allow IPs from the countries my users are coming from as well.. Pfblocker can really shine here as how to maintain lists for such use.
And another thing that uses should take away from reading such an article is the value of looking at logs.. Both firewall, and the services you have exposed to catch IPs that are talking to your services that shouldn't be..
-
@AndyRH Most of the time the info came from the domain registrar, especially if one didn't register the domain as private, as it has to be public info.
-
@AndyRH said in Why you are scanned so soon:
I found it interesting that if you get a certificate for your web site you are publicly announced and apparently scanned immediately by the bad guys.
Ask for a certificate (a very public thing) from some CA, then know that they, the CA's, have to add you to the unique list, the same list half the computer related part of Havard (university in the US) is tapped into so they obtain data for their theses.
Something like that.@johnpoz said in Why you are scanned so soon:
would be valuable to the bad guys
Hey, these guys are the future good guys, right ? No ?
Anyway : you use an IPv4 : you get 'scanned'. Most of it is innocent.