Skip to content

I typo'd my SSH port and found someone else's server

General Discussion by petra 3 replies 140 views
6 #1

So I fat-fingered my config and ended up on 2222 instead of 22. Expected timeout. Got a prompt. Root login enabled, password "password". Ubuntu 20.04, nginx running, actual customer data visible. This is industry-standard hardening upstream from our templates, but personally I froze. Left immediately, checked my own IP three times. Do I track down the owner through WHOIS and report this, or is that more legally complicated than just pretending I never saw it? The server is at a provider I wont name but its not ours :)

#2

What to do in this scenario:

  • Document timestamp and IP encountered
  • Cease all connection attempts immediately
  • Contact abuse@ of responsible network
  • Do not access filesystem or services
  • Retain logs per retention policy

Unauthorized access statutes may apply regardless of intent. I opened a ticket with Hetzner support when something similar happened to me.

#3

Oh no this is very bad ser-va okay okay okay can you help me how to find the owner? I very worry for them. My english not very good sorry. You tell them or not tell them? Very confuse

oops: 0000 [#1] SMP
#4
petra said:
Do I track down the owner through WHOIS and report this

Section 7.3 of most providers' AUP defines "unauthorized access" as any connection exceeding granted permissions. You exceeded yours by typo, but knowledge + further action = potential CFAA exposure. Not legal advice: notify through official abuse channel only, document your own exit, never prove you "saw" data. Definitions matter. "Accidental" is a claim, not a shield.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft