Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Shodan found Dropbear

    Scheduled Pinned Locked Moved Firewalling
    16 Posts 5 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MoonKnight @WhoAmI68
      last edited by

      @WhoAmI68

      Okay, Why not try to do a port check again from https://www.grc.com/x/ne.dll?bh0bkyd2
      Just to make sure the port is closed.
      Maybe day have been scanning you from a new IP? I'm sure they get some new servers and then do some more scan before other found out :)

      92a34e5c-e686-4083-b090-fc2eb7d83de0-image.png

      --- 24.11 ---
      Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
      Kingston DDR4 2666MHz 16GB ECC
      2 x HyperX Fury SSD 120GB (ZFS-mirror)
      2 x Intel i210 (ports)
      4 x Intel i350 (ports)

      W 1 Reply Last reply Reply Quote 0
      • W
        WhoAmI68 @MoonKnight
        last edited by

        @MoonKnight said in Shodan found Dropbear:

        www.grc.com

        As I said before, I have made scan from outside, it is closed, so the pfblocker take it. Anyway shodan logs that It doesn't just happen :).

        johnpozJ 1 Reply Last reply Reply Quote 0
        • tinfoilmattT
          tinfoilmatt @WhoAmI68
          last edited by

          @WhoAmI68 said in Shodan found Dropbear:

          Can anyone have an explanation for me, how is this possible

          It's not.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @WhoAmI68
            last edited by johnpoz

            @WhoAmI68 said in Shodan found Dropbear:

            Anyway shodan logs that It doesn't just happen :).

            Did you maybe have a unifi ap open to the internet. Did/do you have a router in front of pfsense that might have had remote access enabled?

            There was just some other thread that popped up that I saw about dropbear from a while ago - pfsense doesn't run dropbear - never has as far back as I can remember.. I don't even believe it did from before it was pfsense, back when it was m0n0wall..

            And that version of dropbear while quite old today.. but for example my unifi APs ran that for longest time- don't get me started on why they haven't updated them in like forever, and when they actually did - it was still old, even when they deployed it.

            Hallway-BZ.6.7.8# ssh -V
            Dropbear v2022.83
            Hallway-BZ.6.7.8# 
            

            the current version is 2024.86, why are unifi AP like 2 year old version? ;)

            On a side note - I block all those known scanner things like shodan.. There is zero reason why they should put into a public DB the ports that are open.. So I block all those shitty scanners..

            edit: good seems my blocks are working, search my pubic IP and got this

            justsearched.jpg

            I have multiple ports open - but screw those guys they have no valid reason to list the ports I have open in a public DB.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            A M W 3 Replies Last reply Reply Quote 2
            • A
              Antibiotic @johnpoz
              last edited by

              @johnpoz said in Shodan found Dropbear:

              So I block all those shitty scanners

              Inbound or both traffic?

              pfSense plus 24.11 on Topton mini PC
              CPU: Intel N100
              NIC: Intel i-226v 4 pcs
              RAM : 16 GB DDR5
              Disk: 128 GB NVMe
              Brgds, Archi

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @Antibiotic
                last edited by

                @Antibiotic why would anything on my network ever be talking to those IPs.. But they do send a lot of inbound traffic, which they don't need to see what ports I have open.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                A 1 Reply Last reply Reply Quote 0
                • A
                  Antibiotic @johnpoz
                  last edited by

                  @johnpoz Ok, Inbound than)))

                  pfSense plus 24.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  1 Reply Last reply Reply Quote 0
                  • M
                    MoonKnight @johnpoz
                    last edited by

                    @johnpoz

                    Same here :) I have been using UniFi for many years now, including switches and APs. I have never enabled UPnP & NAT-PMP on pfSense to prevent the automatic opening of ports from various devices that use UPnP :)

                    fa7d6e7e-64a1-4e84-b976-5405129e9d2e-image.png

                    --- 24.11 ---
                    Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                    Kingston DDR4 2666MHz 16GB ECC
                    2 x HyperX Fury SSD 120GB (ZFS-mirror)
                    2 x Intel i210 (ports)
                    4 x Intel i350 (ports)

                    1 Reply Last reply Reply Quote 0
                    • W
                      WhoAmI68 @johnpoz
                      last edited by

                      @johnpoz

                      @johnpoz said in Shodan found Dropbear:

                      Did you maybe have a unifi ap open to the internet.

                      No, i didn't.

                      @johnpoz said in Shodan found Dropbear:

                      Did/do you have a router in front of pfsense that might have had remote access enabled?

                      Yes, ISP routers have remote access. However, they do not use port 2222.

                      @johnpoz said in Shodan found Dropbear:

                      On a side note - I block all those known scanner things like shodan.. There is zero reason why they should put into a public DB the ports that are open.. So I block all those shitty scanners..

                      I use Spamn DB list to block Shodan, Apollo etc. So In this situation, I do not understand how it was possible to scan.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @WhoAmI68
                        last edited by

                        @WhoAmI68 said in Shodan found Dropbear:

                        I use Spamn DB list to block Shodan

                        what? How is that going to block it?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        W 1 Reply Last reply Reply Quote 0
                        • W
                          WhoAmI68 @johnpoz
                          last edited by

                          @johnpoz Normally like ipset or pfblocker feeds list :).

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @WhoAmI68
                            last edited by johnpoz

                            @WhoAmI68 and why would you think the scanning IPs from shodan would be in a spam db?? Do you think they also send spam from these IPs?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            W 1 Reply Last reply Reply Quote 0
                            • W
                              WhoAmI68 @johnpoz
                              last edited by

                              @johnpoz At abuseipdb.com you can check it out.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.