Abuse reports: IPv6 ENTRO scanning alert
Over the last days, I have received a number of abuse reports for "network scanning" for services related to my dnscry.pt project.
I'm honestly surprised how easy it is to get a provider to shut down a server just by sending something like this:
Network scanning alert notification
Target address:2a0e:bc00::185:xxxx:xxxx:xxxx-->CETNET2 IPv6 Networks
Protocol type:ENTRO
Number of scans:1,612
Recording time:2025-05-29 00:51:47Please check the security configuration of related network devices in time.
This is an automatic email. Please contact [email protected] or [email protected] if you have any questions.
Network security team Rein240c
I have no idea what this is about and couldn't find any useful information. I tried to contact the email addresses in the report without success.
Has anyone received similar reports and knows what this is about? Does anyone know what CETNET2 or the ENTRO protocol is?
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
Comments
Which provider acts on that? Have you asked that provider to explain the abuse report (if they act on it, they must have understood it).
Never heard of an ENTRO protocol either.
CETNET2 is probably a typo of CERNET2
https://www.nodeseek.com/post-352255-1
The scan amount is the same, haha.
Looks like, somebody is checking, which providers accepts bullshit abuse emails.
@Brueggus what providers did accept that as valid abuse?
Free NAT KVM | Free NAT LXC
No, I didn't bother. It's obvious to me that they don't care about the content and just forward the messages.
Until now...
I am pretty sure that I'll receive more.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
I received that too and asked reporter for more details, they didn't respond since Friday, May 30
Original complaint below (sent from
[email protected]
):Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden
Could this be just another weird university "research" project? It all doesn't make any sense to me.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
Yes, send fake abuse, check if the IP stops pinging.
If yes, we write that down.
Free NAT KVM | Free NAT LXC
Research Projects are wild, here's one I got a real while back from TU Dresden:
At least these are still helpful, no idea what the hell happened with the abuse reports.
youtube.com/watch?v=k1BneeJTDcU