Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - macege

#1
I can confirm it has been resolved after turning of the old firewall.
#2
Dude, I finally figured out why I was seeing these results. When I setup opnsens I left my old firewall running and this have port forward to port 22 on my ubuntu. The machine is trying to answer on its default route and sends everything to opnsense.

Before you arrest me, I use fail2ban to block bruteforce attempts.

Damn, took me awhile before I could understand why my ubuntu was trying to make all these connections through  opnsense.

I will shutdown the old router and let you know if this solves the problem. I'm pretty sure it does (I'm not home now)
#3
Thanks, I have some investigating or possible reinstall. I will try to find out how they got in the first place.

I did some portscan on the reported IP's and some have port 22 open. I guess my ubuntu is used for some brute force purpose.

I would never see this if it was not for the opnsense firewall log. (I just installed it on Tuesday.)
#4
Is my device hacked?

Ubuntu - media server, sending lots of requests from port 22. Or am i understanding the firewall direction wrong?

Please check attachment.