Community discussions

MikroTik App
 
davidreaton
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 88
Joined: Thu Oct 02, 2014 12:21 am

Access attempts from ShadowServer

Wed May 11, 2022 7:35 pm

I have 3 mikrotik routers (3011, 4011 and CCR1016) at 3 sites. All show access attempts from IPs that lead to a site called 'shadowserver'.

IPs are 64.62.197.93, 94, 80, 14 and 74.82.47.4 and others. See the attached images for the log and shadowserver page.

Has anyone heard of this? Any action necessary?

Help appreciated,
Dave
Log.jpg
Shadowserver.jpg
You do not have the required permissions to view the files attached to this post.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19321
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Access attempts from ShadowServer

Wed May 11, 2022 8:26 pm

Well, that is expected if one has VPNs open to the world, bots or others will find your IP address and attempt to connect on those ports.
Nothing unusual there but all the more reason to use Solid VPN mechansims and not something known to be weak such PPTP etc.............
I prefer wireguard and changing the port to something obscure compared to the fixed ports of other types, as I dont need the complexity of certificates etc.....
 
User avatar
memelchenkov
Member Candidate
Member Candidate
Posts: 202
Joined: Sun Oct 11, 2020 12:00 pm
Contact:

Re: Access attempts from ShadowServer

Wed May 11, 2022 8:37 pm

Once I tried to mitigate attacks from DigitalOcean network. I tried to reach their abuse/security department very hard with no adequate reaction. In my opinion, it was a serious issue, with a real malicious activity. It seems, ShadowServer works on opposite side—they try to make the Internet more secure, they are "white hackers". If I correctly understand their nature, of course.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19321
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Access attempts from ShadowServer

Wed May 11, 2022 9:38 pm

Or are they bad actors merely posing as white hackers, who knows these days. :-)
 
davidreaton
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 88
Joined: Thu Oct 02, 2014 12:21 am

Re: Access attempts from ShadowServer

Wed May 11, 2022 11:04 pm

I'm using Windows 10 built in VPN to access these machines remotely using L2TP-IPsec with PSK.

Another user suggested a reboot for these routers, and this stopped the failed access attempts. They hadn't been rebooted for more than 30 days. Any suggested changes I should look at?

Thanks,
Dave

Who is online

Users browsing this forum: DanMos79, haedertowfeq, Jörg, kg5iru, monotsc, unhuzpt and 56 guests