Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Shodan found Dropbear

    Scheduled Pinned Locked Moved Firewalling
    16 Posts 5 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      WhoAmI68
      last edited by WhoAmI68

      Hi all,
      After I have checked my IP address by Shodan, It has been found that port 2222 is open with the dropbear daemon.
      It is very interesting to see because WAN is close. I do not use ssh, so ssh is disabled. Also, the Dropbear is not installed.

      Below are some pics from the test.
      Shodan:
      Drop.png
      Sockstat:
      sockstat.png
      Ssh:
      ssh.png
      Dropbear:
      dropb.png

      I also checked port 2222 from the outside. It was closed.

      I found this post on the forum:
      https://forum.netgate.com/topic/173161/dropbear-ssh-server
      I think the guy had a similar problem but In any case, he didn't explain it.

      Can anyone have an explanation for me, how is this possible or What is going on?

      I tried asking my ISP but They are still checking :).
      Thanks for help.

      M tinfoilmattT 2 Replies Last reply Reply Quote 0
      • M
        MoonKnight @WhoAmI68
        last edited by MoonKnight

        @WhoAmI68
        Maybe someone had your IP before you got it?
        Look at the date 2024-10-24

        --- 24.11 ---
        Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
        Kingston DDR4 2666MHz 16GB ECC
        2 x HyperX Fury SSD 120GB (ZFS-mirror)
        2 x Intel i210 (ports)
        4 x Intel i350 (ports)

        W 1 Reply Last reply Reply Quote 0
        • W
          WhoAmI68 @MoonKnight
          last edited by

          @MoonKnight No :), I have the IP address for half the year.
          I use some Spamn DB list so it is block Shodan or Apollo etc. So in this situation, I do not understand How it was possible to do a scan from their side :).
          Maybe ISP's router has been hacked?
          ISP use of some port for remote service. In any case, there is still no explanation.

          M 1 Reply Last reply Reply Quote 0
          • M
            MoonKnight @WhoAmI68
            last edited by

            @WhoAmI68

            Okay, Why not try to do a port check again from https://www.grc.com/x/ne.dll?bh0bkyd2
            Just to make sure the port is closed.
            Maybe day have been scanning you from a new IP? I'm sure they get some new servers and then do some more scan before other found out :)

            92a34e5c-e686-4083-b090-fc2eb7d83de0-image.png

            --- 24.11 ---
            Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
            Kingston DDR4 2666MHz 16GB ECC
            2 x HyperX Fury SSD 120GB (ZFS-mirror)
            2 x Intel i210 (ports)
            4 x Intel i350 (ports)

            W 1 Reply Last reply Reply Quote 0
            • W
              WhoAmI68 @MoonKnight
              last edited by

              @MoonKnight said in Shodan found Dropbear:

              www.grc.com

              As I said before, I have made scan from outside, it is closed, so the pfblocker take it. Anyway shodan logs that It doesn't just happen :).

              johnpozJ 1 Reply Last reply Reply Quote 0
              • tinfoilmattT
                tinfoilmatt @WhoAmI68
                last edited by

                @WhoAmI68 said in Shodan found Dropbear:

                Can anyone have an explanation for me, how is this possible

                It's not.

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @WhoAmI68
                  last edited by johnpoz

                  @WhoAmI68 said in Shodan found Dropbear:

                  Anyway shodan logs that It doesn't just happen :).

                  Did you maybe have a unifi ap open to the internet. Did/do you have a router in front of pfsense that might have had remote access enabled?

                  There was just some other thread that popped up that I saw about dropbear from a while ago - pfsense doesn't run dropbear - never has as far back as I can remember.. I don't even believe it did from before it was pfsense, back when it was m0n0wall..

                  And that version of dropbear while quite old today.. but for example my unifi APs ran that for longest time- don't get me started on why they haven't updated them in like forever, and when they actually did - it was still old, even when they deployed it.

                  Hallway-BZ.6.7.8# ssh -V
                  Dropbear v2022.83
                  Hallway-BZ.6.7.8# 
                  

                  the current version is 2024.86, why are unifi AP like 2 year old version? ;)

                  On a side note - I block all those known scanner things like shodan.. There is zero reason why they should put into a public DB the ports that are open.. So I block all those shitty scanners..

                  edit: good seems my blocks are working, search my pubic IP and got this

                  justsearched.jpg

                  I have multiple ports open - but screw those guys they have no valid reason to list the ports I have open in a public DB.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  A M W 3 Replies Last reply Reply Quote 2
                  • A
                    Antibiotic @johnpoz
                    last edited by

                    @johnpoz said in Shodan found Dropbear:

                    So I block all those shitty scanners

                    Inbound or both traffic?

                    pfSense plus 24.11 on Topton mini PC
                    CPU: Intel N100
                    NIC: Intel i-226v 4 pcs
                    RAM : 16 GB DDR5
                    Disk: 128 GB NVMe
                    Brgds, Archi

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @Antibiotic
                      last edited by

                      @Antibiotic why would anything on my network ever be talking to those IPs.. But they do send a lot of inbound traffic, which they don't need to see what ports I have open.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      A 1 Reply Last reply Reply Quote 0
                      • A
                        Antibiotic @johnpoz
                        last edited by

                        @johnpoz Ok, Inbound than)))

                        pfSense plus 24.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        1 Reply Last reply Reply Quote 0
                        • M
                          MoonKnight @johnpoz
                          last edited by

                          @johnpoz

                          Same here :) I have been using UniFi for many years now, including switches and APs. I have never enabled UPnP & NAT-PMP on pfSense to prevent the automatic opening of ports from various devices that use UPnP :)

                          fa7d6e7e-64a1-4e84-b976-5405129e9d2e-image.png

                          --- 24.11 ---
                          Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                          Kingston DDR4 2666MHz 16GB ECC
                          2 x HyperX Fury SSD 120GB (ZFS-mirror)
                          2 x Intel i210 (ports)
                          4 x Intel i350 (ports)

                          1 Reply Last reply Reply Quote 0
                          • W
                            WhoAmI68 @johnpoz
                            last edited by

                            @johnpoz

                            @johnpoz said in Shodan found Dropbear:

                            Did you maybe have a unifi ap open to the internet.

                            No, i didn't.

                            @johnpoz said in Shodan found Dropbear:

                            Did/do you have a router in front of pfsense that might have had remote access enabled?

                            Yes, ISP routers have remote access. However, they do not use port 2222.

                            @johnpoz said in Shodan found Dropbear:

                            On a side note - I block all those known scanner things like shodan.. There is zero reason why they should put into a public DB the ports that are open.. So I block all those shitty scanners..

                            I use Spamn DB list to block Shodan, Apollo etc. So In this situation, I do not understand how it was possible to scan.

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @WhoAmI68
                              last edited by

                              @WhoAmI68 said in Shodan found Dropbear:

                              I use Spamn DB list to block Shodan

                              what? How is that going to block it?

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              W 1 Reply Last reply Reply Quote 0
                              • W
                                WhoAmI68 @johnpoz
                                last edited by

                                @johnpoz Normally like ipset or pfblocker feeds list :).

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator @WhoAmI68
                                  last edited by johnpoz

                                  @WhoAmI68 and why would you think the scanning IPs from shodan would be in a spam db?? Do you think they also send spam from these IPs?

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                                  W 1 Reply Last reply Reply Quote 0
                                  • W
                                    WhoAmI68 @johnpoz
                                    last edited by

                                    @johnpoz At abuseipdb.com you can check it out.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.