Challenge HN: There's only one truly open port on this machine. Can you find it?

11 points by u53314109 ↗ HN
Came up with some fun iptables rules for securing my servers and I'd like to test out how effective they are, so here's a challenge for you all!

There's a VPS on 152.70.178.90 with a quite unique firewall configuration. Open to the internet are two services: an HTTP server on :80 for verifying my ownership of the machine, and... something else, somewhere. Your task is to find and connect to the second service – bonus points if you successfully authenticate. (yeah, I know I said only one port but c'mon, the HTTP server doesn't count)

There's no port knocking, fail2ban, or anything like that. The port is always open for everyone to see. The VPS is also on a gigabit connection, so go wild! Just don't purposefully DDoS it please, for the sake of everyone else.

Also, you're more than welcome to crosspost this on reddit, lemmy, or wherever else! I'll likely release the iptables config once someone gets in and documents how.

13 comments

[ 4.3 ms ] story [ 54.8 ms ] thread
Running a quick nmap shows all ports as open, yet i tried to connect to some manually to no avail. Is there a better way to to automatically test all of them?
I would look at the nmap doc, there are tests that connect to the port.
likely part of the challenge. has some kind of ids/ips that reports all ports as open.
That's the point of this post. Look at the packet headers for each return packet. Look for a difference in TTL, for example.
Be real careful about running nmap on public ips. ISPs can ban for that.
Brand new account posts a challenge to HN, which isn't really a thing we do here, asking for people to document how to pen test a server.

Another brand new account jumps in to participate, but again is asking for help on how to pen test.

Looks legit.

I know it's not really a thing, but I do know that there are quite a few capable people that frequent the site and all of this is advanced enough that posting it to somewhere like r/hacking seemed pointless. What I came up with seemed really interesting to me, so I thought it could be interesting to someone else here, idk. I also didn't want to just reveal exactly what I did to not spoil the fun.

I also really wasn't looking for help on how to pentest, I think I'm pretty capable as is. The server has such an unusual firewall config though (even outside the 'all ports look open to a basic `nmap -sS`' stuff) that I thought it could be a nice learning experience for folks, or something.

That other account is an irl friend of mine.

port 80, its open, there i win
Bringing the server down now, since nobody seems to actually care & I don't want to just waste server resources.