Server Security Concerns and Request for Assistance

Lucas Teodoro2 years ago

Hello everyone, I hope you are doing well. By the way, Anton, thank you for this wonderful software. In advance, I apologize for my English; my native language is Portuguese. I've noticed from the server logs that random devices are trying to connect to the server, devices that I don't have and haven't pointed to the server. I only use GT06, and I see several devices from other protocols attempting to connect. How can I block these attempts, as there are many, and it's causing server overload? Here are the records:

2023-10-19 13:02:25  INFO: [T1129c41f] connected
2023-10-19 13:02:25  INFO: [T1129c41f: t800x < 65.49.20.118] 010000000002000d0100007530
2023-10-19 13:02:25  INFO: [T1129c41f] error - Adjusted frame length (0) is less than lengthFieldEndOffset: 5 - CorruptedFrameException (... < WrapperInboundHandler:57 < ... < StandardLoggingHandler:44 < ... < NetworkMessageHandler:37 < ...)
2023-10-19 13:02:25  INFO: [T1129c41f] disconnected
2023-10-19 13:34:34  INFO: [T3a958043] connected
2023-10-19 13:34:34  INFO: [T3a958043: cartrack < 167.94.138.36] 16030100ee010000ea030398da1da0270f56e4b41d810e7f4f6e13f22040be159b728a04c0420ee72d1f2020e5731a7ff1a7f00352dcadf2c03cb164cd1402e90e06cc267e99f7dc9cd855be0026cca8cca9c02fc030c02bc02cc013c009c014c00a009c009d002f0035c012000a1303130113020100007b000500050100000000000a000a0008001d001700180019000b00020100000d001a0018080404030807080508060401050106010503060302010203ff0100010000120000002b0009080304030303020301003300260024001d00200227795444f922b65a2e38356f3018b81bc3043ea1d65ab6a11e66fd9963bf26
2023-10-19 13:34:44  INFO: [T3a958043] error - Connection reset - SocketException (...)
2023-10-19 13:34:44  INFO: [T3a958043] disconnected
2023-10-19 13:34:44  INFO: [Tb0d7b06e] connected
2023-10-19 13:34:45  INFO: [Tb0d7b06e] error - Connection reset - SocketException (...)
2023-10-19 13:34:45  INFO: [Tb0d7b06e] disconnected
2023-10-19 13:34:45  INFO: [T46a84332] connected
2023-10-19 13:34:45  INFO: [T46a84332: cartrack < 167.94.138.36] 16030100ee010000ea0303201bded3a3fe8f9551094650124854c6a6a440f74b9f6d28c0e7cfb1981e67a720b897c4407b8f70544df3d674ee8ff96645899ff9a450409e08778831f861fc8e0026cca8cca9c02fc030c02bc02cc013c009c014c00a009c009d002f0035c012000a1303130113020100007b000500050100000000000a000a0008001d001700180019000b00020100000d001a0018080404030807080508060401050106010503060302010203ff0100010000120000002b0009080304030303020301003300260024001d0020214aa3724de85258b6ee340878b32f9a5915d60602b2eb63bc6ee734d4e7b523
2023-10-19 13:34:48  INFO: [T46a84332] error - Connection reset - SocketException (...)
2023-10-19 13:34:48  INFO: [T46a84332] disconnected
2023-10-19 13:34:48  INFO: [T952a2d14] connected
2023-10-19 13:34:49  INFO: [T952a2d14: cartrack < 167.94.138.36] 474554202f20485454502f312e310d0a486f73743a20352e3136312e36302e3136343a353036310d0a0d0a
2023-10-19 13:34:52  INFO: [T952a2d14] error - Connection reset - SocketException (...)
2023-10-19 13:34:52  INFO: [T952a2d14] disconnected
2023-10-19 13:34:52  INFO: [T1d363634] connected
2023-10-19 13:34:52  INFO: [T1d363634] error - Connection reset - SocketException (...)
2023-10-19 13:34:52  INFO: [T1d363634] disconnected
2023-10-19 15:07:57  INFO: [T461c9928] connected
2023-10-19 15:07:57  INFO: [T461c9928: gs100 < 94.102.61.49] 474554202f20485454502f312e310d0a486f73743a20352e3136312e36302e3136343a353232330d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38382e302e343332342e313930205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a
2023-10-19 15:08:06  INFO: [T922548a3] connected
2023-10-19 15:08:06  INFO: [T922548a3: xrb28 < 94.102.61.49] 474554202f20485454502f312e310d0a486f73743a20352e3136312e36302e3136343a353138300d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38382e302e343332342e313930205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a
2023-10-19 15:08:06  INFO: [T922548a3] error - begin 9, end 24, length 14 - StringIndexOutOfBoundsException (... < Xrb28ProtocolDecoder:71 < ExtendedObjectDecoder:75 < ... < WrapperContext:102 < ...)
2023-10-19 15:08:06  INFO: [T922548a3] error - begin 9, end 24, length 23 - StringIndexOutOfBoundsException (... < Xrb28ProtocolDecoder:71 < ExtendedObjectDecoder:75 < ... < WrapperContext:102 < ...)
2023-10-19 15:08:06  WARN: Unknown device - t: Mozilla/5.0  (94.102.61.49)
2023-10-19 15:08:06  INFO: [T922548a3] error - begin 9, end 24, length 11 - StringIndexOutOfBoundsException (... < Xrb28ProtocolDecoder:71 < ExtendedObjectDecoder:75 < ... < WrapperContext:102 < ...)
2023-10-19 15:08:06  INFO: [T922548a3] error - begin 9, end 24, length 21 - StringIndexOutOfBoundsException (... < Xrb28ProtocolDecoder:71 < ExtendedObjectDecoder:75 < ... < WrapperContext:102 < ...)
2023-10-19 15:08:06  INFO: [T922548a3] error - begin 9, end 24, length 0 - StringIndexOutOfBoundsException (... < Xrb28ProtocolDecoder:71 < ExtendedObjectDecoder:75 < ... < WrapperContext:102 < ...)
Anton Tananaev2 years ago

If your server is exposed to internet, it's expected that you will get some random noise.

One thing you can do is disable ports that you don't use.

But overall I wouldn't worry about it unless you get too many random messages.

Lucas Teodoro2 years ago

Thank you Anton. I will disable the unused ports.