Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ShadowServer Coming From My IP?

    General pfSense Questions
    4
    8
    880
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ArkTechA
      ArkTech LAYER 8
      last edited by ArkTech

      Hello! I saw a strange connection coming from my pfSense and decided to lookup that IP and saw it belonged to a service called ShadowServer.

      37007760-f3e6-4c8c-81a4-3bb22e731007-image.png

      d578542e-9ff9-48ec-b18a-8c9ea4efb9e0-image.png

      They are just collecting data and giving it to governments & bidders I assume.
      Is this coming from my network? Thank you

      Edit: Read more on it, making me even more confused why it appears to be originating from my IP? Is this something my ISP has power to do?
      From what ShadowServer describes, they connect to you not the other way around. Thank you

      1 Reply Last reply Reply Quote 1
      • NollipfSenseN
        NollipfSense
        last edited by

        You can block it.

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • ArkTechA
          ArkTech LAYER 8
          last edited by

          Thank you for the response, am I reading it wrong that it's coming from my IP?

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by NogBadTheBad

            Do you have any sort of port forwarding going on ?

            What's firewall rule 197 ?

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • ArkTechA
              ArkTech LAYER 8
              last edited by ArkTech

              @NogBadTheBad said in ShadowServer Coming From My IP?:

              Do you have any sort of port forwarding going on ?

              What's firewall rule 197 ?

              I'm not sure what firewall rule 197 is, I've never made a NAT or rule named that and I went over all my rules.

              7e202ff0-76f3-41fb-90d5-a19af97dae12-image.png

              8ea68410-562d-45bc-9047-707c8953bd66-image.png

              Those are the only rules on my INTERNET interface

              I do have other rules but that traffic goes through my GRE tunnels instead of my INTERNET, and they're not 197 either or get connected to via my IP. Very strange!

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Check Diag > pfTop > View: Rules

                Outbound traffic would normally always be passed and not logged by default though.

                Steve

                ArkTechA 1 Reply Last reply Reply Quote 0
                • ArkTechA
                  ArkTech LAYER 8 @stephenw10
                  last edited by

                  @stephenw10
                  Thank you Stephen, next time I find traffic like that I'll go there and check. I didn't know about that tool!

                  I couldn't find the IP when I searched it as "src" or "dst" network 184.105.139.118/32

                  I'll keep an eye out, I just don't want something like that coming out of my network because I'd suspect one of my machines got hacked into!
                  Thank you for all the responses

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Unless you have changed the rules since taking that screen shot you should still be able to see what rule 197 is.

                    It must be a custom rule of some sort as that would not otherwise be logged.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.