Recently enabled Snort on my firewall and found that Zoneminder on startup and periodicaly is contacting 34.177.186.192 on port 443
This is flagged as a Network Trogan, Do we know why Zoneminder is contacting this IP address?
1.36.33 getting flagged by Snort
-
- Posts: 1336
- Joined: Sat Aug 31, 2019 7:35 am
- Location: San Diego
Re: 1.36.33 getting flagged by Snort
That's an AWS ip, pretty sure it's the ZM telemetry. Which is down due to expense.
There used to be a checkbox to turn it off. I suspect if you go to Options->Privacy->(choose) Decline, then Apply, that will stop it.
Port 443 is the normal https:// port, BTW.
There used to be a checkbox to turn it off. I suspect if you go to Options->Privacy->(choose) Decline, then Apply, that will stop it.
Port 443 is the normal https:// port, BTW.
Re: 1.36.33 getting flagged by Snort
Yes is the privacy option. states it contact ipinfo.io which i saw in the wireshark capture. I have declined it, will see if it trys to contact it again.
443 HTTPS same same...
443 HTTPS same same...