[App_rpt-users] Incoming connects

Johnny Keeker cypresstower at yahoo.com
Sun Jan 12 17:11:20 UTC 2014


I had a port forwarding issue with a Xipar node on its own ISP. I bypassed the router for testing purposes ONLY. The router was blocking the ports.  Seeing I had to wait for another router to arrive, I decided to leave the node unprotected just to see if Hackers would actually find it.  With in a day, there were so many hits, I couldn't type a single character without it scrolling off the screen.  I let it run away with itself until I got another router, then powered down the modem, hooked up the router. I waited before applying power to the modem. I got a different IP, everything was fine after that.....     
JK  
knowledge is experience!!!  


________________________________
From: Lu Vencl <vencl at att.net>
To: Jim W7RY <w7ry at centurytel.net> 
Cc: "app_rpt-users at ohnosec.org" <app_rpt-users at ohnosec.org> 
Sent: Sunday, January 12, 2014 7:48 AM
Subject: Re: [App_rpt-users] Incoming connects



Hope you at least have employed a firewall such as via webmin.  Hackers are likely to be targeting your box some day. Just saying from experience. 

Sent from my iPhone, Lu Vencl

On Jan 12, 2014, at 1:00 AM, Jim W7RY <w7ry at centurytel.net> wrote:


One of the very first things to do when testing connection issues is to put the node in the DMZ of the router. Easy, simple and can quickly eliminate lots of settings.

In fact, my node is on the DMZ with a strong password. Never had an issue.

73
Jim W7RY


On 1/11/2014 7:21 PM, Doug Crompton wrote:

OK I think this is solved. Unfortunately it is hard to diagnose all problems when you have an inexperienced person at the other end. 
>
>It turns out the router was forwarding the right port BUT it was set to tcp instead of udp.  I had gone over this several times with the operator and I had thought it was right but when we looked at it again it was wrong.
>
>When set in the tcp mode it did accept connections but only for a short window of time after a prior disconnect from the other direction.
>
>Thanks for all the input and sorry to cause all the back and forth on this. I learned that you have to be extremely concise when dealing with someone remotely who is inexperienced! 
>
>73 Doug
>WA3DSP
>http://www.crompton.com/hamradio
>
>
>
>
>________________________________
>Subject: Re: [App_rpt-users] Incoming connects
>From: tim.sawyer at mac.com
>Date: Fri, 10 Jan 2014 20:29:46 -0800
>CC: app_rpt-users at ohnosec.org
>To: doug at crompton.com
>
>Do a “tcpdump port 4569” at the Linux command line and incite a connect from another node. You should see inbound packets. 
>
>
>I have seen ISP’s block port 4569 but not FiOS. I’m on FiOS with an actiontek router and it works fine.
>
>--
>Tim
>:wq
>
>On Jan 10, 2014, at 7:41 PM, Doug Crompton <doug at crompton.com> wrote:
>
>I am remotely trying to troubleshoot a friends new Allstar installation.  I can ssh in and connect out to nodes but I cannot connect in to the system from external nodes. Port 4569 is forwarded.
>>
>>I discovered this link -
>>
>>http://www.voip-info.org/wiki/view/IAX
>>
>>about consistent NAT and I was wondering if that might be the problem.
>>
>>I was able to connect in one time right after a reboot which might support the NAT issue.
>>
>>The router is an Actiontek MI424WR GigE  as supplied by Verizon on their FIOS system.
>>
>>Is anyone else having a problem with this router or have any ideas on this? 
>>
>>Nothing is logged at the server or shows up in the client on the system which kind of points to a routing failure.
>>
>>Is there a good way to check for open port 4569 as I don't think normal port scan programs will check this.
>>
>>73 Doug
>>WA3DSP
>>http://www.crompton.com/hamradio
>>_______________________________________________
>>App_rpt-users mailing list
>>App_rpt-users at ohnosec.org
>>http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
>
> 
>
>_______________________________________________
App_rpt-users mailing list App_rpt-users at ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users 

_______________________________________________
>App_rpt-users mailing list
>App_rpt-users at ohnosec.org
>http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
>

_______________________________________________
App_rpt-users mailing list
App_rpt-users at ohnosec.org
http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.keekles.org/pipermail/app_rpt-users/attachments/20140112/ffa98818/attachment.html>


More information about the App_rpt-users mailing list