Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wasipwned
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
wasipwned
4y ago
Not to my knowledge, but I will double checking to make sure. The odd part is the issue only started recently, but I haven't made any major changes to my network recently.
2.
▲
by
wasipwned
4y ago
Yes I posted the IP address here: https://news.ycombinator.com/item?id=33820749 and it appears to be AT&T's CGNAT IP address and communicating over port 4500 (IPsec), so the likely culprit is Wi-Fi calling which us
3.
▲
by
wasipwned
4y ago
I can't explain this part yet. I was asleep when this happened, so I wasn't even using my phone. I may be wrong about 300Mbps being to the AT&T. public IP, as my router shows a much lower rate. That might have just been the to
4.
▲
by
wasipwned
4y ago
I can't fully explain this part yet, but I am currently expecting that I will see the issue again even with my desktop disconnected. I am also probably wrong about it being 300Mbps to AT&T. It was probably 300Mbps of multicast traf
5.
▲
by
wasipwned
4y ago
Out of curiosity, how do you know it's CGNAT? Is it just because all of AT&T's mobile traffic is through CGNAT?
6.
▲
by
wasipwned
4y ago
False alarm. Really appreciate everyone helping me sanity check this. The randomized MAC is part of iOS' Wi-Fi privacy, and my phone is using Wi-Fi calling for AT&T. The randomized MAC and the fact that I thought I saw the traffic
7.
▲
by
wasipwned
4y ago
Thanks for reminding me of this. This is looking less and less malicious at this point as `10.0.0.3` is my phone (using AT&T, which is where all the traffic was destined).
8.
▲
by
wasipwned
4y ago
Yeah, I'm now realizing that this might be multicast traffic I'm seeing from another device, and I do use AT&T which is making me think this may not actually be malicious.
9.
▲
by
wasipwned
4y ago
I probably am mistaken that it's originating from my desktop. It is entirely possible that it is multicast traffic I am seeing. See https://news.ycombinator.com/item?id=33821387
10.
▲
by
wasipwned
4y ago
Circling back, this discussion thread seems to be the most likely culprit. In my panicked state, I didn't even consider multicast traffic being the reason why I saw this traffic in tcpdump. I'm digging into this a bit more. I prob
11.
▲
by
wasipwned
4y ago
Unfortunately, I did not save any packet captures, so I only saw that it was on the IPsec port.
12.
▲
by
wasipwned
4y ago
This actually makes the most sense so far. I hadn't even considered the possibility of multicast. Let me see if I can dig in further.
13.
▲
by
wasipwned
4y ago
Yeah, that was exactly what I was thinking as well. I do use KVM to run a few VMs, but they were the only VMs I could find, and they were both stopped the whole time.
14.
▲
by
wasipwned
4y ago
I had run lsof on my desktop and I did not see any of the IP addresses in question. I did not check specifically for port 4500 though.
15.
▲
by
wasipwned
4y ago
I'm using a UDM Pro, and I had just recently patched. The only container running on the router is unifi-os itself. I keep repeating myself because I want to make sure I can't be missing something, but tcpdump on my desktop is show
16.
▲
by
wasipwned
4y ago
Ethernet, and wifi is disabled. But even if it was wifi or another network interface getting the IP, I should have been able to find it in ip a / ifconfig I'm assuming
17.
▲
by
wasipwned
4y ago
Not running BGP that I'm aware of. Network is comprised of mostly UniFi switches and one MikroTik switch.
18.
▲
by
wasipwned
4y ago
And by looking it's coming from my desktop, I mean the tcpdump was run directly on my desktop and I saw the traffic there. So I assume it had to be routed through my desktop unless I am missing something.
19.
▲
by
wasipwned
4y ago
So interestingly, it looks like Unifi did classify the traffic as wifi calling, but it was doing a lot of traffic in the middle of the night when I was asleep. And the biggest question mark in my head is: how is this traffic looking like it
20.
▲
by
wasipwned
4y ago
There are corporate laptops on my network. I had originally thought maybe that could be related. But I can't explain how this source IP was showing up on a tcpdump from my desktop if that was the case, so at this point I'm assumin
21.
▲
by
wasipwned
4y ago
Yes and yes.
22.
▲
by
wasipwned
4y ago
It was given an IP via DHCP (but not that specific IP, that was more for illustrative purposes). I'm currently ruling out that it is any other device given I'm seeing the traffic from my desktop, and it shouldn't be acting as
23.
▲
by
wasipwned
4y ago
Nothing is exposed directly to the internet, but I had some development services that were accessible on my private network. I do use Dropbox, but the odd part was it seemingly IPsec traffic. I really should have grabbed a pcap when it was
24.
▲
by
wasipwned
4y ago
Yeah. That's definitely the plan, but I want to see if there's anything I can learn from the machine before I even do so. The IP address was 107.122.31.71.
25.
▲
Ask HN: Was I pwned? [resolved]
189 points
by
wasipwned
4y ago
|
88 comments