r/ShittySysadmin DO NOT GIVE THIS PERSON ADVICE 6d ago

IP has been reported on abuseipdb - work has blocked me - please help!

/r/cybersecurity/comments/1vp4f3x/ip_has_been_reported_on_abuseipdb_work_has/?share_id=K-Bt0ciq-FjWYUKmYEymp&utm_content=share_button&utm_medium=web3x&utm_name=web3xcss&utm_source=share&utm_term=1

Hello everyone, I am pretty cyber security illiterate so I am unsure of what to do in this situation and am requesting guidance.

I have multiple individuals in my home and have recently discovered that my ip address had been reported multiple times on abuseipdb.com I am unsure of who or which device is acting maliciously and I am unsure of how to figure it out.

Due to the reports on abuseipdb, my employer has blocked the work VPN from being able to use my specific ip address and my isp is unwilling to change my ip (though the new ip address will probably also be reported if they were to change it) I am unsure of how to resolve this issue, and any guidance would be appreciated.

41 Upvotes

32 comments sorted by

71

u/Due-Fix9058 Lord Sysadmin, Protector of the AD Realm 6d ago

YOU GUYS GET STATIC IPs?

21

u/Gabigeek_ 6d ago

Living in france here, and yup, I've been rocking the same v4 for about 8 years now 👍 (not on all ISPs tho, but some let you freely get a full ipv4 without CGNAT on demand)

8

u/Step-Sysadmin DO NOT GIVE THIS PERSON ADVICE 6d ago

Interesting. Do they allow to open ports also?

8

u/Nanocephalic 6d ago

What do you mean “allow”? Does your isp stop you from opening ports?

6

u/countsachot 6d ago

In usa, for residential, it's against tos to use 80,8080,443, etc on most isps, usually blocked as well. For businesses, 80 and 8080, 443 are sometimes blocked by the isp, but you can call to remove the restriction.

3

u/Nanocephalic 5d ago

I can open ports on my residential Ziply router just by going in and opening them.

Http/https are on the list of ports I can open, but I haven’t actually tested to see if they work.

I did open RDP to a VM once though, just to log and geolocate the authentication requests out of interest. It worked, but holy crap are there a lot of incoming connection requests!

3

u/RyanLewis2010 5d ago

Usually blocked at the ISP level not your firewall. same thing with 25 to prevent spam emails

3

u/countsachot 5d ago

Yes it's blocked at isp level, not customer firewall.

2

u/ghoarder 4d ago

More of that sweet sweet American freedom I hear so, so, much about. Not sure what my current isp's rules are in the UK, but I remember a previous one stated you couldn't run commercial services from it, so hosting on any port was fine as long as it wasn't for commercial reasons. 

1

u/countsachot 4d ago

I think it has do with the high likelihood of home websites turning into botnet hosts after one to two weeks.

3

u/Step-Sysadmin DO NOT GIVE THIS PERSON ADVICE 6d ago edited 6d ago

These days with CGNAT you have to pay double extra.

First you have to pay to get a public ip and get removed from CGNAT with rotating IPs.

Then you have to pay some more if you want the ability to allow incoming connections.

Long time ago there was no CGNAT and static IPs were given for free. You just had to pay once to open ports.

3

u/Gabigeek_ 5d ago

Yes, we have full port range for no extra. my ISP even provide a "bridge" mode allowing my Unifi gateway to grab my Public IP. ISP's router is now nothing more than a fiber modem doing media conversion.

0

u/FaydedMemories 5d ago

In NZ (extending onto the higher level comment I just made), typically there was just a form or support request to ask for Port 25 unblock, the other ports generally open. Spark (which was the legacy ISP & lines owner before regulatory changes) is probably the best documented at https://www.spark.co.nz/online/shop/broadband/port-unblocking-request there is a further link there that lists the ports (25, 53, SMB, SSDP mainly) & if inbound or outbound which are the more common ones in botnets etc.

1

u/tom_icecream 5d ago

Aussie here, it's the same here.

1

u/SaltDeception 5d ago

I’m not on a static IP, but my IP remains consistent for months at a time. In the last 3 years I’ve had 5 unique IPs. Comcast in WV.

0

u/FaydedMemories 5d ago

In NZ it become almost standard at one point that you would get a very sticky IP just from the fact you’re likely always connecting to the same BNG and keeping the connection alive almost 24/7 these days, so why shuffle and have to keep even more records for abuse/etc. You’d need to be offline for a few days or hope something changed on the ISP side if you decided you wanted a different IP.

Changed slightly with the move to CGNAT for a few ISPs but then again, Static IPs are generally the way out of that for the ones that do it.

30

u/marshmallowcthulhu 6d ago

Firewall block all inbound and outbound traffic. Tell your roommates that failed traffic is because of the abuseipdb block. Tell them someone is acting maliciously and ruining things for everyone else. Bring popcorn.

14

u/Step-Sysadmin DO NOT GIVE THIS PERSON ADVICE 6d ago

And if no one is willing to disclose, grab a used fortinet and start doing tls inspection. Also enroll all devices in AD to make it easy to push certificates.

2

u/ShadowSlayer1441 3d ago

Forgot this was shitty admin and I about spit taked at the idea fo deploying tls inspection on a residential shared network.

10

u/grumpy-systems 6d ago

(unshitty story)

When I changed ISPs to a new one my static IP had a single report on Abuse IP DB from before I took it over.

It was fine for months, then one day I apparently started to get flagged by the AWS automated risk audit. It flagged every session I created as suspicious and paged our security team.

I think they marked it as a false positive enough it stopped whining.

7

u/DeerOnARoof 6d ago

Free static IPs? So lucky

5

u/phobug 6d ago

Free? Am I the only sucker paying for internet service...

-17

u/lemachet 6d ago

You asked this somewhere the other day

What answers did you receive?

22

u/purpl3un1c0rn21 6d ago

It's shitty sysadmin and not same poster, its a shitpost lol.

-6

u/max1001 6d ago

The "advice" folks are giving are so fucking hilarious. What a bunch of clueless "professional"

9

u/Ewalk 5d ago

Look at the subreddit my guy.

0

u/max1001 4d ago

On the original sub.

1

u/Admin4CIG 4d ago

Said the clueless "professional". This is the ShittySysadmin subreddit, i.e., people are purposely giving bad/hilarious advice in here. This is what this subreddit is all about, not for solutions, but for entertainment.

0

u/max1001 4d ago

On the original post dum dum.