FTP Server--how are people finding me?

Discussions about anything Computer Hardware Related. Overclocking, underclocking and talk about the latest or even the oldest technology. PCA Reviews feedback
Post Reply
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

FTP Server--how are people finding me?

Post by Hipnotic_Tranz »

I'm running an FTP server for my own personal use (mainly so if I go to a friends house and forget a .cfg file or something, I can easily get it). I'm lookin' at the log and am seeing a bunch of IP's I don't recognize (not any of my friends IPs) so how are these people finding my IP? I have it password protected but people still try to guess it or log-in anonymously and it's just annoying. I don't even know how they are finding my FTP server. I mean, I know it's not hard to find my IP but how many people really sit around and try to http://ftp.xxx.xxx.xxx for every IP they come across?
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
PreDatoR
Life Member
Posts: 5554
Joined: Wed Nov 22, 2000 8:01 pm

Post by PreDatoR »

chances are its just someone scanning your range for a open anonymous ftp server... It happens on the underground anonymous public servers are used to upload stuff too... then posted for others to download the stuff until a sysops finds it and deletes it... Don't ask me how i know... lol
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

Basically, as Pred said, people are scanning ports and finding an open port 21 (probably) and then trying to login. I say that you should change your port to a weird port that most people wouldn't scan by default.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

Good idea, I'll just change the port # and see how things go. Thanks :)
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
NascarFool
Posts: 3263
Joined: Thu Nov 23, 2000 1:21 pm

Post by NascarFool »

Were you using port 21 ? Also, are you running a firewall ?
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

Yes and Yes
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
NascarFool
Posts: 3263
Joined: Thu Nov 23, 2000 1:21 pm

Post by NascarFool »

Never use port 21. Not sure how high you can go, I have seen 5 digit ports. What firewall are you using ? I use Norton Internet Security and no one get's in unless I authorize the connection.
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

2121 works. Avoid p2p ports. i've seen 5 digit ports also. most games use 5 digit ports.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

I'm using ZoneAlarm Pro. I changed the port number and I haven't seen any weird IP's in the log, so it looks like it worked. Thanks :D
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
TruckStuff
Golden Member
Posts: 1056
Joined: Thu Feb 07, 2002 5:17 pm
Location: Dallas, TX

Post by TruckStuff »

Security through obscruity (i.e. changing ports for common services) is no security at all. Part of running an FTP server (or any server for that matter) that is connected to the internet is that people will find it and try to access it. That is why you have users, groups, etc. setup: to allow some people and deny others. While changing the port of the service may get you fewer "connection attempt from x.x.x.x" entires in your log files, it certainly will not prevent anyone from "finding" your server.
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

Thats all I'm looking for though. I got tired of so many anonymous people tryin' to get in. I have passwords on all my users/groups because this server is for me and my friends only. I mean, the login/password I made for my friends is very simple and some even guessed it, thats why I wanted to find out how these people were finding me and if there was a way to "hide" myself, so to speak.
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
TruckStuff
Golden Member
Posts: 1056
Joined: Thu Feb 07, 2002 5:17 pm
Location: Dallas, TX

Post by TruckStuff »

If people are successfully guessing the passwords, you have another problem to worry about. Passwords that are easily guessed are extermely poor and defeat the entire purpose of having users and passwords. If someone can guess them correctly, you need to change them immediately. Passwords are your first line of defense and compromising them is how 95% of system breakins begin. Simply changing the port may keep the really stupid script kiddies out, but even a somewhat stupid script kiddie will get around that.

Besides, I like seeing all those access denied in my logs. Lets my know that my security measures are working the way they should. :)
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

Well, the login/password for my friends group is very simple and I really didn't care that they cracked in (not at all surprised really). That group has no more access than to look at what I have and download it. They can't upload/rename/make directories/etc. I kept the login/password simple so my friends can remember it.

My account on the other hand has a fairly simple username but the password is one I doubt anybody could figure out. The only reason I set a username/password in my friends account in the first place was to keep these anonymous people away....then they started guessing and when they were finally getting in thats when I got fed up and was wondering how they found me in the first place.... ...thus my post began :)

Ever since my port change, I haven't seen one UIP (unidentified IP ;) ) in my log, though.
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
Post Reply