Page 1 of 1

Hacking attempt??

Posted: Tuesday 30 January 2018 9:39
by febalci
Using 3.8153 stable on raspberry 3B. Also using port 8080 via the DDNS provider dynu.com which the port is open on the router. I am having Domoticz log as follows:

Code: Select all

2018-01-29 14:01:30.803  Incoming connection from: 78.179.40.13
2018-01-29 14:21:43.038  Incoming connection from: 155.94.146.2
2018-01-29 15:10:47.664  Incoming connection from: 209.126.136.4
2018-01-29 15:19:58.958  Incoming connection from: 54.165.59.7
2018-01-29 15:36:20.170  Incoming connection from: 95.143.199.43
2018-01-29 16:07:47.824  Incoming connection from: 66.118.142.179
2018-01-29 16:44:23.689  Incoming connection from: 192.168.31.40
I suspect these are attempts to find a proxy since most proxies are using port 8080. Ok can use 8443 which is safer using https, but i was just wondering if any of you are having such log details, esp who are still using port 8080? Since there are no double exposures (double ip), i think there's no reattempts. Btw, these ip's are definitely not me...

Re: Hacking attempt??

Posted: Tuesday 30 January 2018 9:47
by emme
Welcome to the internet!!!

I have tons of them!
it just mean that the port have been contacted which is not a real hack attempt

if you have subcribed a dDNS that's why you get such requests

there is normally nothing to fear about... but in some particular cases (I had few) I banned IPs and networkd form my firewall