Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Shodan found Dropbear

    Scheduled Pinned Locked Moved Firewalling
    16 Posts 5 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      WhoAmI68 @MoonKnight
      last edited by

      @MoonKnight said in Shodan found Dropbear:

      www.grc.com

      As I said before, I have made scan from outside, it is closed, so the pfblocker take it. Anyway shodan logs that It doesn't just happen :).

      johnpozJ 1 Reply Last reply Reply Quote 0
      • tinfoilmattT
        tinfoilmatt @WhoAmI68
        last edited by

        @WhoAmI68 said in Shodan found Dropbear:

        Can anyone have an explanation for me, how is this possible

        It's not.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @WhoAmI68
          last edited by johnpoz

          @WhoAmI68 said in Shodan found Dropbear:

          Anyway shodan logs that It doesn't just happen :).

          Did you maybe have a unifi ap open to the internet. Did/do you have a router in front of pfsense that might have had remote access enabled?

          There was just some other thread that popped up that I saw about dropbear from a while ago - pfsense doesn't run dropbear - never has as far back as I can remember.. I don't even believe it did from before it was pfsense, back when it was m0n0wall..

          And that version of dropbear while quite old today.. but for example my unifi APs ran that for longest time- don't get me started on why they haven't updated them in like forever, and when they actually did - it was still old, even when they deployed it.

          Hallway-BZ.6.7.8# ssh -V
          Dropbear v2022.83
          Hallway-BZ.6.7.8# 
          

          the current version is 2024.86, why are unifi AP like 2 year old version? ;)

          On a side note - I block all those known scanner things like shodan.. There is zero reason why they should put into a public DB the ports that are open.. So I block all those shitty scanners..

          edit: good seems my blocks are working, search my pubic IP and got this

          justsearched.jpg

          I have multiple ports open - but screw those guys they have no valid reason to list the ports I have open in a public DB.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          A M W 3 Replies Last reply Reply Quote 2
          • A
            Antibiotic @johnpoz
            last edited by

            @johnpoz said in Shodan found Dropbear:

            So I block all those shitty scanners

            Inbound or both traffic?

            pfSense plus 24.11 on Topton mini PC
            CPU: Intel N100
            NIC: Intel i-226v 4 pcs
            RAM : 16 GB DDR5
            Disk: 128 GB NVMe
            Brgds, Archi

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Antibiotic
              last edited by

              @Antibiotic why would anything on my network ever be talking to those IPs.. But they do send a lot of inbound traffic, which they don't need to see what ports I have open.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              A 1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @johnpoz
                last edited by

                @johnpoz Ok, Inbound than)))

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • M
                  MoonKnight @johnpoz
                  last edited by

                  @johnpoz

                  Same here :) I have been using UniFi for many years now, including switches and APs. I have never enabled UPnP & NAT-PMP on pfSense to prevent the automatic opening of ports from various devices that use UPnP :)

                  fa7d6e7e-64a1-4e84-b976-5405129e9d2e-image.png

                  --- 24.11 ---
                  Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                  Kingston DDR4 2666MHz 16GB ECC
                  2 x HyperX Fury SSD 120GB (ZFS-mirror)
                  2 x Intel i210 (ports)
                  4 x Intel i350 (ports)

                  1 Reply Last reply Reply Quote 0
                  • W
                    WhoAmI68 @johnpoz
                    last edited by

                    @johnpoz

                    @johnpoz said in Shodan found Dropbear:

                    Did you maybe have a unifi ap open to the internet.

                    No, i didn't.

                    @johnpoz said in Shodan found Dropbear:

                    Did/do you have a router in front of pfsense that might have had remote access enabled?

                    Yes, ISP routers have remote access. However, they do not use port 2222.

                    @johnpoz said in Shodan found Dropbear:

                    On a side note - I block all those known scanner things like shodan.. There is zero reason why they should put into a public DB the ports that are open.. So I block all those shitty scanners..

                    I use Spamn DB list to block Shodan, Apollo etc. So In this situation, I do not understand how it was possible to scan.

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @WhoAmI68
                      last edited by

                      @WhoAmI68 said in Shodan found Dropbear:

                      I use Spamn DB list to block Shodan

                      what? How is that going to block it?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      W 1 Reply Last reply Reply Quote 0
                      • W
                        WhoAmI68 @johnpoz
                        last edited by

                        @johnpoz Normally like ipset or pfblocker feeds list :).

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @WhoAmI68
                          last edited by johnpoz

                          @WhoAmI68 and why would you think the scanning IPs from shodan would be in a spam db?? Do you think they also send spam from these IPs?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          W 1 Reply Last reply Reply Quote 0
                          • W
                            WhoAmI68 @johnpoz
                            last edited by

                            @johnpoz At abuseipdb.com you can check it out.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.