[tor-relays] What to do about port scans?
Steve Snyder
swsnyder at snydernet.net
Wed Jul 31 20:14:53 UTC 2013
On 07/31/2013 03:50 PM, mick wrote:
> On Wed, 31 Jul 2013 14:48:05 -0400
> Steve Snyder <swsnyder at snydernet.net> allegedly wrote:
>
>> I wouldn't have thought that the Tor network was fast enough for port
>> scanning, but apparently it is. I have recently seen a rash of SSH
>> port scanning (or so my ISP reports). What can/should I do about
>> this?
>
> I'm not sure exactly what you are saying here.
>
> 1. Do you mean that the scans (directed at you) all came from tor exit
> nodes?
>
> 2. Or do you mean that your tor node was scanned from elsewhere?
>
> 3. Or do you mean that your tor exit node was used in port scanning
> someone else?
[snip]
Sorry for my lack of clarity. I meant that my exit node is being used
for port scans (lots of port 22 doorknob shaking), which has occasioned
recent complaints from my ISP.
More information about the tor-relays
mailing list