Constant Connection attempts from random trackers

automods3 years ago

I have been using Traccar for a few years now, but at the moment I am using it for just one device on a VPS , I was notified today they had shut down my VPS due to to high demand and abuse of bandwidth.

I had a look through the logs and it appears that I am getting lots of random connections from other tracking devices that are nothing to do with me, I have also checked that no extra users have opened accounts either, has anyone ever seen this before ?

I have pasted a small section of the log showing some of the connections and errors, the only device that should be connecting is the tk103 with the ID 027045332723 all of the rest are random devices

2021-04-22 00:07:06  INFO: [8c2b734c] connected
2021-04-22 00:07:06  INFO: [8c2b734c: eelink < 185.153.199.105] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2021-04-22 00:07:06  WARN: [8c2b734c] error - Adjusted frame length exceeds 1024: 12079 - discarded - TooLongFrameException (... < WrapperInboundHandler:57 < ... < StandardLoggingHandler:43 < ... < NetworkMessageHandler:37 < ...)
2021-04-22 00:07:06  INFO: [8c2b734c] disconnected
2021-04-22 00:09:12  INFO: [c165dbef] connected
2021-04-22 00:09:12  INFO: [c165dbef: tk103 < 82.132.225.102] HEX: 283032373034353333323732334250303533353532323730343533333237323332313034323141353131362e393332384e30303131362e35343935453030302e303233303931303030302e303030313030303030304c303030303030303029
2021-04-22 00:09:12  INFO: [c165dbef: tk103 > 82.132.225.102] HEX: 283032373034353333323732334150303529
2021-04-22 00:09:12  INFO: [c165dbef] id: 027045332723, time: 2021-04-22 00:09:10, lat: 51.28221, lon: 1.27583, course: 0.0
2021-04-22 00:10:42  INFO: [36992406] connected
2021-04-22 00:11:55  INFO: [5723ae47] connected
2021-04-22 00:11:55  INFO: [5723ae47: upro < 185.153.199.105] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2021-04-22 00:13:13  WARN: [f4a67be8] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 00:13:13  INFO: [f4a67be8] disconnected
2021-04-22 00:20:12  INFO: [068c7101] connected
2021-04-22 00:24:48  WARN: [84e11a3e] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 00:24:48  INFO: [84e11a3e] disconnected
2021-04-22 00:30:46  INFO: [a9c850b2] connected
2021-04-22 00:30:46  INFO: [a9c850b2: tk103 < 82.132.234.255] HEX: 283032373034353333323732334250303533353532323730343533333237323332313034323141353131362e393332374e30303131362e35353238453030302e303233333034313030302e303030313030303030304c303030303030303029
2021-04-22 00:30:46  INFO: [a9c850b2: tk103 > 82.132.234.255] HEX: 283032373034353333323732334150303529
2021-04-22 00:30:46  INFO: [a9c850b2] id: 027045332723, time: 2021-04-22 00:30:41, lat: 51.28221, lon: 1.27588, course: 0.0
2021-04-22 00:32:13  INFO: [d0f27468] connected
2021-04-22 00:32:15  WARN: [a00ba34a] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 00:32:15  INFO: [a00ba34a] disconnected
2021-04-22 00:33:57  WARN: [a9c850b2] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 00:33:57  INFO: [a9c850b2] disconnected
2021-04-22 00:41:43  INFO: [7bd8b945] connected
...
2021-04-22 08:09:45  INFO: [0e3706a8] connected
2021-04-22 08:09:45  INFO: [0e3706a8: tk103 < 82.132.223.152] HEX: 283032373034353333323732334250303533353532323730343533333237323332313034323241353131362e393334364e30303131362e35353035453030302e303037303933383030302e303030313030303030304c303030303030303029
2021-04-22 08:09:45  INFO: [0e3706a8: tk103 > 82.132.223.152] HEX: 283032373034353333323732334150303529
2021-04-22 08:09:45  INFO: [0e3706a8] id: 027045332723, time: 2021-04-22 08:09:38, lat: 51.28224, lon: 1.27584, course: 0.0
2021-04-22 08:11:10  INFO: [8763ede1] connected
2021-04-22 08:11:29  WARN: [71831ea0] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:11:29  INFO: [71831ea0] disconnected
2021-04-22 08:12:09  WARN: [0e3706a8] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:12:09  INFO: [0e3706a8] disconnected
2021-04-22 08:16:49  WARN: [b36a75bd] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:16:49  INFO: [b36a75bd] disconnected
2021-04-22 08:18:33  INFO: [e5434b4e] connected
2021-04-22 08:18:33  INFO: [e5434b4e: tk103 < 194.61.55.248] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2021-04-22 08:20:41  INFO: [c0ffb2f5] connected
2021-04-22 08:21:31  WARN: [8763ede1] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:21:31  INFO: [8763ede1] disconnected
2021-04-22 08:21:46  WARN: [28d47a51] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:21:46  INFO: [28d47a51] disconnected
2021-04-22 08:23:06  INFO: [54665021] connected
2021-04-22 08:23:06  INFO: [54665021] disconnected
2021-04-22 08:26:36  WARN: [6c8bf065] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:26:36  INFO: [6c8bf065] disconnected
2021-04-22 08:31:16  INFO: [55178c99] connected
2021-04-22 08:31:16  INFO: [55178c99: tk103 < 82.132.232.89] HEX: 283032373034353333323732334250303533353532323730343533333237323332313034323241353131362e393331324e30303131362e35353431453030302e313037333131303030302e303030313030303030304c303030303030303029
2021-04-22 08:31:16  INFO: [55178c99: tk103 > 82.132.232.89] HEX: 283032373034353333323732334150303529
2021-04-22 08:31:16  INFO: [55178c99] id: 027045332723, time: 2021-04-22 08:31:10, lat: 51.28219, lon: 1.27590, speed: 0.1, course: 0.0
2021-04-22 08:32:17  INFO: [8dc534a1] connected
2021-04-22 08:32:17  INFO: [8dc534a1: sanav < 213.108.134.156] HEX: d41646d696e697374720d0a0100080003000000
2021-04-22 08:32:42  INFO: [0036cbde] connected
2021-04-22 08:32:50  WARN: [3a864250] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:32:50  INFO: [3a864250] disconnected
2021-04-22 08:42:03  INFO: [df258419] connected
2021-04-22 08:42:03  INFO: [df258419: xirgo < 213.108.134.156] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2021-04-22 08:42:12  INFO: [9f6cf5e9] connected
2021-04-22 08:43:20  INFO: [57738951] connected
2021-04-22 08:43:20  INFO: [57738951] disconnected
2021-04-22 08:46:08  INFO: [20034763] connected
2021-04-22 08:46:09  INFO: [20034763] disconnected
2021-04-22 08:52:46  INFO: [bab196dd] connected
2021-04-22 08:52:46  INFO: [bab196dd: tk103 < 82.132.215.227] HEX: 283032373034353333323732334250303533353532323730343533333237323332313034323241353131362e393333334e30303131362e35353038453030302e313037353234313030302e303030313030303030304c303030303030303029
2021-04-22 08:52:46  INFO: [bab196dd: tk103 > 82.132.215.227] HEX: 283032373034353333323732334150303529
2021-04-22 08:52:46  INFO: [bab196dd] id: 027045332723, time: 2021-04-22 08:52:41, lat: 51.28222, lon: 1.27585, speed: 0.1, course: 0.0
2021-04-22 08:54:13  INFO: [5d26a9ab] connected
2021-04-22 08:55:58  WARN: [bab196dd] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:55:58  INFO: [bab196dd] disconnected
2021-04-22 08:56:08  INFO: [d0bf97b3] connected
2021-04-22 08:56:09  INFO: [d0bf97b3] disconnected
2021-04-22 08:56:32  WARN: [e5434b4e] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 08:56:32  INFO: [e5434b4e] disconnected
2021-04-22 09:00:52  WARN: [fd5cffbf] error - An existing connection was forcibly closed by the remote host - IOException (...)
2021-04-22 09:00:52  INFO: [fd5cffbf] disconnected
2021-04-22 09:01:23  INFO: [c3d55b29] connected
2021-04-22 09:01:23  INFO: [c3d55b29: gt02 < 185.153.199.105] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2021-04-22 09:01:23  WARN: [c3d55b29] error - readerIndex(5) + length(8) exceeds writerIndex(5): PooledSlicedByteBuf(ridx: 5, widx: 5, cap: 5/5, unwrapped: PooledDirectByteBuf(ridx: 5, widx: 47, cap: 1024)) - IndexOutOfBoundsException (... < Gt02ProtocolDecoder:59 < ExtendedObjectDecoder:51 < ... < WrapperContext:102 < ...)
2021-04-22 09:01:23  WARN: [c3d55b29] error - readerIndex(5) + length(8) exceeds writerIndex(5): PooledSlicedByteBuf(ridx: 5, widx: 5, cap: 5/5, unwrapped: PooledDirectByteBuf(ridx: 10, widx: 47, cap: 1024)) - IndexOutOfBoundsException (... < Gt02ProtocolDecoder:59 < ExtendedObjectDecoder:51 < ... < WrapperContext:102 < ...)
Anton Tananaev3 years ago

It's probably just random noise, like connections from port scanners etc. I would recommend closing ports that you don't use.

automods3 years ago

Many Thanks will do :)

Funny how it identifies real tracker names will have a mad port closing session in a minute:)