GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Thursday, 07-Nov-2024 15:19:09 JST翠星石翠星石
    in reply to
    • Georg Engelmann
    @georgengelmann There is an attacker spoofing TCP packets with the source IP to pretend to mass-connect to ssh honeypots - meaning that Tor relays are getting TCP RST packets and abuse reports.

    Such attack shouldn't be possible, but BCP38 has seen little implementation.

    It's best to reply to such abuse reports noting that such was an IP spoofing attack and none of such connections came from your server.

    https://forum.torproject.org/t/tor-relays-tor-relays-source-ips-spoofed-to-mass-scan-port-22/15498 (too bad you cannot view the issue comments without running proprietary gitlab JavaScript).
    In conversationabout 7 months ago from freesoftwareextremist.compermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: forum.torproject.org
      [tor-relays] Tor relays source IPs spoofed to mass-scan port 22?
      Hi relay ops, A few hours ago I received a forwarded abuse report from Hetzner for one of my machines running a Tor relay (not exit). Some random ISP was claiming I was sending SSH connections to them, and at first I couldn't find any corroborating evidence in my own network logs and I was ready to dismiss it. But then I noticed that there is in fact something weird: all 4 of my machines running Tor relays are seeing *return* TCP traffic (RSTs or SYN-ACKs) from port 22 from various machi...
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.