Jump to content

Torrenting: Weird open ports?

babadoctor

Hello

 

Let's say that I have a port open because of UPNP due to me torrenting a file. 

 

Is an attacker able to see any information about the torrent client from my ip address?

 

I can browse to my local IP address and put in the UPNP port, and it shows me a bunch of garbled text.

 

Any idea what this is?

 

image.thumb.png.e3b787a2f0e98554059bb8928fce1b31.png

OFF TOPIC: I suggest every poll from now on to have "**CK EA" option instead of "Other"

Link to comment
Share on other sites

Link to post
Share on other sites

When you torrent a file other people can see your ip. Hell when I open utorrent I can see the ip of everyone im connected to and even a little flag sometimes of where its from. Want privacy with that theres a lot of options but the best is VPN. I don't however think its common to be attacked because of this. I also don't believe any port being open would effect that as I believe every router has well known ports open.

Edit: source I work with the networking stuff at my college. I don't know as much as a professional but I know that a open port and a ip address doesn't ment you can be attacked.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Ohsnaps said:

When you torrent a file other people can see your ip. Hell when I open utorrent I can see the ip of everyone im connected to and even a little flag sometimes of where its from. Want privacy with that theres a lot of options but the best is VPN. I don't however think its common to be attacked because of this. I also don't believe any port being open would effect that as I believe every router has well known ports open.

You misunderstand my question.

 

I want to understand what information can be gained from someone seeing this port open

OFF TOPIC: I suggest every poll from now on to have "**CK EA" option instead of "Other"

Link to comment
Share on other sites

Link to post
Share on other sites

I don't believe anything can be gained. I get what you're saying but when a server fails and you try to connect to it sometimes you get garbled text. That doesn't mean its useful even to devs. In terms of what that information is I honestly don't know if 100% any answer can be given as it can vary from router to router, os to os, and various other things.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Ohsnaps said:

I don't believe anything can be gained. I get what you're saying but when a server fails and you try to connect to it sometimes you get garbled text. That doesn't mean its useful even to devs. In terms of what that information is I honestly don't know if 100% any answer can be given as it can vary from router to router, os to os, and various other things.

The garbled text obviously means something.

 

I just want to know what.

OFF TOPIC: I suggest every poll from now on to have "**CK EA" option instead of "Other"

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, babadoctor said:

The garbled text obviously means something.

 

I just want to know what.

It could be because the webrowser or text file can't read that encoding of text. UTF-8 tends to be the main thing I know that has mass support. That link might be of some help but I have literally no idea how to backtract to what that actually means especially since I don't have the original only what that program attempted to say it was.

https://en.wikipedia.org/wiki/UTF-8

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, BlueScope819 said:

Can you generate a file with that? Like not just paste it into a file but it seems like it should be formatted as something else. If you open it in a hex editor and look at the header you can figure out what filetype it's supposed to be.

https://en.wikipedia.org/wiki/List_of_file_signatures

I can use wget to attempt to retrieve the file, but wget says there are no headers, and that there is a read error at a specific byte, or something like that.

 

This is what the output looks like.

 

image.png.cd5d7df6a9a347cb95638026527bf604.png

OFF TOPIC: I suggest every poll from now on to have "**CK EA" option instead of "Other"

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, BlueScope819 said:

No I mean like it doesn't matter what it thinks the file is, as long as you can dump it into some type of file then use https://hexed.it/ to look at the header contents

It doesn't seem to have header contents when i do as you said.

Unless I am making some sort of mistake

 

image.png.ee82e17bd47f4f4cc7d4cd69332813c4.png

OFF TOPIC: I suggest every poll from now on to have "**CK EA" option instead of "Other"

Link to comment
Share on other sites

Link to post
Share on other sites

"While a router normally blocks incoming connections, preventing some malicious access, UPnP could allow a malicious program to bypass the firewall entirely. For example, a Trojan horse could install a remote control program on your computer and open a hole for it in your routers firewall, allowing 24/7 access to your computer from the Internet. If UPnP were disabled, the program couldn’t open the port – although it could bypass the firewall in other ways and phone home."

 

Now I don't really know the extent of how dangerous UPNP truly is, someone else might have to elaborate on that. I'm not sure if people can connect to you if you have an open port (from UPNP) available, from a torrent, I don't believe so? But I could be completely wrong.

 

 

Gaming Build:

CPU: Ryzen 7 3800x   |  GPU: Asus ROG STRIX 2080 SUPER Advanced (2115Mhz Core | 9251Mhz Memory) |  Motherboard: Asus X570 TUF GAMING-PLUS  |  RAM: G.Skill Ripjaws DDR4 3600MHz 16GB  |  PSU: Corsair RM850x  |  Storage: 1TB ADATA XPG SX8200 Pro, 250GB Samsung 840 Evo, 500GB Samsung 840 Evo  |  Cooler: Corsair H115i Pro XT  |  Case: Lian Li PC-O11

 

Peripherals:

Monitor: LG 34GK950F  |  Sound: Sennheiser HD 598  |  Mic: Blue Yeti  |  Keyboard: Corsair K95 RGB Platinum  |  Mouse: Logitech G502

 

Laptop:

Asus ROG Zephryus G15

Ryzen 7 4800HS, GTX1660Ti, 16GB DDR4 3200Mhz, 512GB nVME, 144hz

 

NAS:

QNAP TS-451

6TB Ironwolf Pro

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, BlueScope819 said:

No idea, I mean I looked at this list of headers and it doesn't seem to be in there.

https://en.wikipedia.org/wiki/List_of_file_signatures

This is beyond my level of forensic analysis at the moment, I would run MalwareBytes.

You seem to misunderstand

 

It's not a virus, it's my torrent client opening a port using UPNP

 

I want to understand what information I can gain from the outside based on the open port

OFF TOPIC: I suggest every poll from now on to have "**CK EA" option instead of "Other"

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×