Strange connection to server

m7 years ago

Hello,
I'm tryying to configure server and during analizying logfile I founded strange connection to my server. Can you say me what is this?

2018-09-11 10:51:29  INFO: [CC01BF0F] connected
2018-09-11 10:51:29 DEBUG: [CC01BF0F: 5002 < 77.72.83.87] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000

2018-09-11 10:59:15  WARN: [CC01BF0F] error - Connection reset by peer - IOException (...)
2018-09-11 10:59:15  INFO: [CC01BF0F] disconnected

after HEX decode:
Cookie: mstshash=Administr

IP Address Location Information For 77.72.83.77
IP Address 77.72.83.77
Host 77.72.83.77
Country Russian Federation
Latitude 55°44'18" N
Longitude 37°36'24" E
(centre of Moscow)

Anton Tananaev7 years ago

I guess someone tried to connect to your server.

m7 years ago

Yes, propabbly. But how is it possible. I'm using vps from few days, nobody know my ip address - I'm just testing it. How it is possible that somebody obtained IP of my server and tryying to connect to it. It looks like connecton from some equipment or software dedicated to traccar (port 5002)?

Anton Tananaev7 years ago

Welcome to internet. It happens all the time. It can be some software that scans some IP address ranges.

m7 years ago

thank's for your answear

MC7 years ago

me too, in all mi 50xx ports.
for what?

2018-09-25 03:24:07 DEBUG: [4d53fb23: 5085 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 03:24:07  WARN: [4d53fb23] error - Adjusted frame length (0) is less than lengthFieldEndOffset: 3 - CorruptedFrameException (... < WrapperInboundHandler:53 < ... < BasePipelineFactory:127 < ... < *:104 < ...)
2018-09-25 03:24:07  INFO: [4d53fb23] disconnected

2018-09-25 04:20:18 DEBUG: [19dca9d8: 5014 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:20:18  WARN: [19dca9d8] error - java.text.ParseException - DecoderException (... < WrapperInboundHandler:53 < ... < BasePipelineFactory:127 < ... < *:104 < ...)
2018-09-25 04:20:18  INFO: [19dca9d8] disconnected

2018-09-25 03:09:31 DEBUG: [48aa814c: 5079 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 03:09:34  INFO: [b855e383] connected

5013 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:17:20 DEBUG: [31147e3e: 

5106 < 109.248.9.5] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 07:50:55  INFO: [6120f4cc] connected

2018-09-25 07:42:09 DEBUG: [c6d8e322: 5100 < 109.248.9.5] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 07:42:09  INFO: [71b17209] connected

2018-09-25 04:23:33 DEBUG: [ffe23d40: 5016 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:23:34  INFO: [d35d60bb] connected

2018-09-25 04:16:50 DEBUG: [c925f4e2: 5013 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:16:52  INFO: [c7f01f33] connected

2018-09-25 04:11:16 DEBUG: [464aa826: 5010 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:11:17  INFO: [8ae14e00] connected

2018-09-25 04:11:16 DEBUG: [464aa826: 5010 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:11:17  INFO: [8ae14e00] connected

2018-09-25 04:05:31 DEBUG: [420c5bcd: 5006 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:06:08  INFO: [1ff1ba55] connected

2018-09-25 04:06:08 DEBUG: [1ff1ba55: 5007 < 5.8.18.70] HEX: 0300002f2ae00000000000436f6f6b69653a206d737473686173683d41646d696e697374720d0a0100080003000000
2018-09-25 04:06:09  INFO: [9e5d0024] connected
MC7 years ago

after HEX decode:

Cookie: mstshash=Administr

If this enters through port 8082 what privileges get in Windows, Linux or traccar?
Create an admin user or something?

It is also strange that the same scaneer comes to two different servers of Traccar.
what do you think?

Anton Tananaev7 years ago

Even if this comes to port 8082, nothing would happen.