Player trying to connect even through whitelist and a ban

I'm hosting a server for me and some friends and I've had 2 accounts from people I don't know trying to connect to the server (although unsuccessfully, getting disconnected constantly), so I decided to put on a whitelist and put our users so no one else could connect, that seemed to work for one of these 2 people, since they now were getting "You are not white-listed on this server!", for the other one however, this didn't seem to work, so I just banned their username (since they are changing their IP constantly), but that didn't work either cuz they keep trying to connect constantly. Is there any solution to this?
No description
99 Replies
Naantam
Naantam2y ago
I have this same exact issue and same exact player too. Unsure who this "cuute" person is and when I try to go to Reddit to get answers, can't view due to the blackout. Hopefully someone here on the Discord knows something. Some reverse snooping shows its a North Korean individual with female skins. Instead of whitelisting, my team and I decided to implement a password instead: https://www.spigotmc.org/resources/serverpass.103396/ Easier to give out a password than it is for someone to wait on you to be whitelisted.
MrMcyeet
MrMcyeet2y ago
cuute is just a server scanner its harmless
trying to connect to the server (although unsuccessfully, getting disconnected constantly)
They arent connecting or trying to, theyre just checking to see if the server responds to the ping The only real way to "block" them is to firewall off their ip but they're harmless, so you can ignore them
Naantam
Naantam2y ago
I'm now curious how the server ping service even got my private server's IP to begin with. I am guessing the bStats?
MrMcyeet
MrMcyeet2y ago
No they just ping every ipv4 Its dead simple to do, it isnt a server ping service
Naantam
Naantam2y ago
I wasn't sure what else to call it. Anywho, I will indeed block the IP with the firewall and hope that stops the console spam. 🙂 Thank you for the info.
MrMcyeet
MrMcyeet2y ago
Itll stop it until they get a new ip which may happen quickly or not
Shadow
Shadow2y ago
note: they get a new batch of ips from completely different hosting services every single day
Naantam
Naantam2y ago
It does look like a different IP than the one they had two days ago.
Shadow
Shadow2y ago
it will be an ongoing battle, good luck sir 🫡
Zaid
Zaid2y ago
Consolespamfixer and just add that as a word in it Should get rid of the spam This is the best thing I can think of
MrMcyeet
MrMcyeet2y ago
Dont use that
Zaid
Zaid2y ago
Unless you wanna constantly block new ips
MrMcyeet
MrMcyeet2y ago
you can hide shit from console with that
Zaid
Zaid2y ago
Isn't that the point
MrMcyeet
MrMcyeet2y ago
i.e. if you block the word Disconnected, any chat messages with that word will be hidden
Zaid
Zaid2y ago
Just add cuute Problem solved? Or am I missing something
MrMcyeet
MrMcyeet2y ago
if I say the word cuute in your chat, those messages dont get logged and if they change names (which is trivial to do), theyll come back
Zaid
Zaid2y ago
Looks like noway to completely block then huh? Best to live with it then
MrMcyeet
MrMcyeet2y ago
Regex matching!
Naantam
Naantam2y ago
Curious if that plugin can block phrases, not just simple words. I just tested logging in and out of my server, which gives different messages rather than the "com.mojang.authlib.GameProfile" message as seen in the server ping account Cuute.
MrMcyeet
MrMcyeet2y ago
I just tested logging in and out of my server, which gives a different message than "com.mojang.authlib.GameProfile" as seen in the server ping account Cuute.
Cause theyre not logging in and back out theyre just pinging the server
Naantam
Naantam2y ago
Right, but if I use that specific phrase, I could potentially hide the ping no matter what user or IP they use.
MrMcyeet
MrMcyeet2y ago
true, but again, if any player says that string in chat their messages wont be logged to console
Naantam
Naantam2y ago
I kind of doubt most of the players I allow into my server would even think to say something like that. Its a friends and friends of friends only server, not open to general public. So the likelihood of that specific phrase is quite small. I'm off for the night. Thank you everyone who has taken their time and expertise to voice opinion and options on this matter. 🙂
mat
mat2y ago
North Korean individual
it's true cuute is kim jong un himself i asked kimmy j and he confirmed it for me who knows why he's playing with female skins
Zaid
Zaid2y ago
Let's be real most play with female skins
MrMcyeet
MrMcyeet2y ago
👉👈 I don't
Zaid
Zaid2y ago
Keyword "most" :]
Shrecknt
Shrecknt2y ago
North Korean individual
can confirm 100% no lie
Deauthorized
Deauthorized2y ago
It's spammy so it isn't harmless Either way I wrote a fail2ban filter for them so they can go and get fucked
Deauthorized
Deauthorized2y ago
No description
Mortis
Mortis2y ago
You should write a guide on how to do it in #resources Some people would probably appreciate it lol
Deauthorized
Deauthorized2y ago
I'll do that later, its three am
Mortis
Mortis2y ago
all good. sleep well
mat
mat2y ago
probably not a good idea to ip ban anyone who fails to authenticate since it can happen in vanilla like if your session expires i think
MrMcyeet
MrMcyeet2y ago
if you hit cancel on a connecting screen it logs that
Mortis
Mortis2y ago
Im pretty sure his one just does it for repeating ones like 5x attempts in < 10 secs
mat
mat2y ago
ah cuute doesn't go that fast anyways though
Mortis
Mortis2y ago
mhm. Either way some people probs could expand on it or just refer to it if they end up going down that route i just personally ignore it nowadays
mat
mat2y ago
just simply don't look at your console 😄👍
Deauthorized
Deauthorized2y ago
From what I was able to test it only logs when plugins cancel the connection Such as discordsrv And yeah I have it set to five logs within 15 minutes since cuute attempts to connect every two minutes for hours on end I'd rather not deal with the log spam
MrMcyeet
MrMcyeet2y ago
no
Deauthorized
Deauthorized2y ago
Oh ok
aadumaaduMC
aadumaaduMC2y ago
How did it find my server? I run it on a different port than 25565 I'm just curious
Philipp
Philipp2y ago
They just check all ips with all ports as simple as that
MstrTaffy
MstrTaffy2y ago
Aren't you one of the people doing it anyway? Would be great to see you stopping it rather than being unhelpful. Yeah we can just "not look at the console" but how are you meant to troubleshoot your server? There is enough spam on there without this nonsense happening.
mat
mat2y ago
it's not me but i do know a lot about scanning
mat
mat2y ago
there's a lot of people that have made scanners cuute only really exists to annoy server owners
MstrTaffy
MstrTaffy2y ago
Not many have entire blog posts about it though https://matdoes.dev/minecraft-scanning
mat
mat2y ago
yes i made a bot that joins servers but it's much nicer than cuute imo have a separate post about that one the actual easiest solution to hiding the console spam is to just firewall their ips though lol
MstrTaffy
MstrTaffy2y ago
I mean, sure, until the VPS gets shutdown and then another one pops up and you play wack a mole every day.
mat
mat2y ago
there's also like at least one plugin that just hides the error messages
Deauthorized
Deauthorized2y ago
Cuute is not an example of a "nice" scanner
mat
mat2y ago
i agree
MstrTaffy
MstrTaffy2y ago
No scanner is a nice scanner. They are pointless spam.
mat
mat2y ago
scanners don't cause console spam the ones that do are usually intentionally trying to annoy you
Deauthorized
Deauthorized2y ago
Also why did you say abuseipdb was a leader board lol
mat
mat2y ago
is that not what it is it's a joke
Deauthorized
Deauthorized2y ago
I and many other services regularly pull from it as a blacklist
mat
mat2y ago
no one follows its rules the abuseipdb rules say you can't report for port scanning yet everyone does literally a joke site
Deauthorized
Deauthorized2y ago
Why is there a report category for port scanning then If it's not allowed lol
mat
mat2y ago
check again wait there is silly abuseipdb
Deauthorized
Deauthorized2y ago
No description
mat
mat2y ago
anyways the point of the website is for reporting malicious activity though
MstrTaffy
MstrTaffy2y ago
I don't see anything in the TOS about not reporting port scanning either
Deauthorized
Deauthorized2y ago
No way It doesn't make sense to write it off as cosmetic when there are actual consequences to being reported by people
mat
mat2y ago
No description
mat
mat2y ago
a lot of port scanning is just sending syn packets and not completing the handshake
MstrTaffy
MstrTaffy2y ago
That's probably because of this : https://i.taffy.coffee/QiUWj4i6BM.png
MstrTaffy
MstrTaffy2y ago
That doesn't mean "IP scanners are fine though"
mat
mat2y ago
i mean port scanning isn't inherently malicious reporting it is a tad silly
MstrTaffy
MstrTaffy2y ago
ah of course, hence why if you do it on Hetzner, they can and will ban your account. Same as many VPS hosts. Silly fools banning people for being spammy "I'm just curious bro, nothing malicious, trust me"
mat
mat2y ago
some hosts ban for scanning because they get complaints from dumb sysadmins that think a SYN packet is going to hack their system and it's easier to just ban than keep dealing with complaints
Deauthorized
Deauthorized2y ago
Its more like the hosts scanning are also correlated to hosts that probe every ipv4 on the internet Probably involved with ssh bruteforcing as well Or minecraft server scanning Nobody scans ipv4 "just cuz"
mat
mat2y ago
you'd be surprised plenty of people scan ipv4 just cause it's fun
MstrTaffy
MstrTaffy2y ago
as I said before "trust me bro"
mat
mat2y ago
um yeah "innocent until proven guilty" right scanning isn't proof of anything malicious
MstrTaffy
MstrTaffy2y ago
Of course not. But who knows what you will do with the information?
Deauthorized
Deauthorized2y ago
Like I said it's correlated to server probers And most hosts would rather not deal with the waste of resources
MstrTaffy
MstrTaffy2y ago
Thats for damn sure
mat
mat2y ago
reporting for ssh bruteforcing is fine
Deauthorized
Deauthorized2y ago
Some people value their privacy
mat
mat2y ago
that's at least probable cause
dami
dami2y ago
me on my way to sue people for defamation after they reported me on abuseipdb
mat
mat2y ago
good idea
dami
dami2y ago
wtf???? someone reoprted me for being cuute??
No description
dami
dami2y ago
ok it is just faked, they replaced the ip in the log there normally isn't a space two spaces before port too why???
Deauthorized
Deauthorized2y ago
If its one account on one address it's fine You can opt out by just nullrouting it I have an issue with scanners that constantly switch ips
mat
mat2y ago
there's several ways to opt out of scanners simplest is to enable the setting that makes you show up as "anonymous player" in the server list ping second simplest is to disable the server list ping in server.properties
Deauthorized
Deauthorized2y ago
Server list ping isnt sent Yeah
Naantam
Naantam2y ago
I wonder if you're Matscan, an account that actually joined my server while I have the password plugin in place. It failed to do the password in time so it got autobanned.
dami
dami2y ago
He's matscan, yes
Naantam
Naantam2y ago
Nice to know that password plug-in works nicely. 😛
Discount Milk
Discount Milk2y ago
You grep out errors you don't care about. Have you never looked at the logs for a public facing apache instance? Or a public facing ssh port? If only tools to parse log files existed.
Shrecknt
Shrecknt2y ago
ever heard of google? yeah that company loves to scan every ipv4 address also microsoft, those guys do it too in fact, ever single search engine does full ipv4 scans regularly ipv4 scanning has plenty of practical uses
dami
dami2y ago
even the BND or the NSA cooperate with scanners
Deauthorized
Deauthorized2y ago
Yes that's how their search engine works I'm aware They have a legit reason
mat
mat2y ago
there was an older version that logged in as all admins and tried the passwords "password" and the player's username i didn't implement that for matscan though

Did you find this page helpful?