Bitcoin Forum
May 05, 2024, 01:22:14 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Allowing Inbound Connections  (Read 111 times)
pawanjain (OP)
Hero Member
*****
Offline Offline

Activity: 2674
Merit: 713


Nothing lasts forever


View Profile
September 26, 2021, 09:51:51 AM
Last edit: May 16, 2023, 02:55:27 AM by pawanjain
Merited by Pmalek (2)
 #1

So I started running a bitcoin full node on my Raspberry Pi 400 around 5 months back and was able to do all the setup required and run the node successfully.
I was feeling happy that I was actually supporting the bitcoin network and the community by running the full node.
But that wasn't the case since we have to relay the information by allowing inbound connections to our full node.
Although I knew we have to allow inbound connections to our full node I thought that was done by default when we setup the full node initially and begin downloading block data.
Today I just thought of checking it back again when I noticed that we actually have to manually setup the router to allow inbound connections.

So I started configuring my router and enabled static IP address for my raspberry pi and enabled port forwarding to port 8333.
When I tested my connection on https://bitnodes.io/ I was still getting the redbox meaning my full node was not allowing inbound connections.
I tried various stuffs and kept verifying the connection on bitnodes as well as CLI but no luck.
It was then that I found out that we have to wait around 10 minutes on bitnodes website and 30 minutes on the CLI to verify the inbound connections.
Long story short I just had to wait for a couple of minutes to verify the connection but I kept experimenting again and again.

Feeling happy now to support the network #again  Grin




P.S : One question though - What are the risks of someone finding our IP address by finding out our node ? Can he potentially exploit our device ?

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
1714915334
Hero Member
*
Offline Offline

Posts: 1714915334

View Profile Personal Message (Offline)

Ignore
1714915334
Reply with quote  #2

1714915334
Report to moderator
1714915334
Hero Member
*
Offline Offline

Posts: 1714915334

View Profile Personal Message (Offline)

Ignore
1714915334
Reply with quote  #2

1714915334
Report to moderator
BitcoinCleanup.com: Learn why Bitcoin isn't bad for the environment
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
ranochigo
Legendary
*
Offline Offline

Activity: 2954
Merit: 4166


View Profile
September 26, 2021, 10:39:39 AM
Merited by ABCbits (1)
 #2

But that wasn't the case since we have to relay the information by allowing inbound connections to our full node.
Running a full node without inbound connections already means that you're relaying blocks and transactions.
Although I knew we have to allow inbound connections to our full node I thought that was done by default when we setup the full node initially and begin downloading block data.
Today I just thought of checking it back again when I noticed that we actually have to manually setup the router to allow inbound connections.
Core by default already listens to that port. If you're behind any firewall, then you have to configure it yourself.
P.S : One question though - What are the risks of someone finding our IP address by finding out our node ? Can he potentially exploit our device ?
Not really. It is only a risk if there is an exploit within whichever application that is listening on the portforwarded port and accepts malicious commands. That is unlikely to happen.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
aliashraf
Legendary
*
Offline Offline

Activity: 1456
Merit: 1174

Always remember the cause!


View Profile WWW
September 26, 2021, 04:34:06 PM
Merited by ABCbits (2)
 #3

please note that in Bitcoin, connections with peers, either inbound or outbound, are full duplex, i.e. it is not strictly needed to have inbound connections for participating in the network though it yields a much better topology, having more nodes advertised as being ready for incoming connection requests.
calchuchesta
Member
**
Offline Offline

Activity: 124
Merit: 11


View Profile
September 26, 2021, 04:54:15 PM
 #4

please note that in Bitcoin, connections with peers, either inbound or outbound, are full duplex, i.e. it is not strictly needed to have inbound connections for participating in the network though it yields a much better topology, having more nodes advertised as being ready for incoming connection requests.

A lot of people disable on the GUI the option of "allow incoming connections" because they are paranoid that this means people are able to connect to your node, gaining personal information, perhaps even performing RPC. I have seen this numerous times:

https://bitcoin.stackexchange.com/questions/98555/what-exactly-does-the-scary-option-allow-incoming-connections-do-in-bitcoin-co

I think it should be clearly explained what it does otherwise we lose potential connectivity from all these people being scared to keep that option checked.
pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10549



View Profile
September 27, 2021, 02:56:33 AM
 #5

When I tested my connection on https://bitnodes.io/
You should now check the clients that are connected to you (incoming) and try to count how many of them are "spy nodes" because last time I did that (not running core) I was spammed with at least 10 of them that kept coming and going and sometimes changing their IP address too.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
pawanjain (OP)
Hero Member
*****
Offline Offline

Activity: 2674
Merit: 713


Nothing lasts forever


View Profile
September 27, 2021, 03:46:27 PM
 #6

When I tested my connection on https://bitnodes.io/
You should now check the clients that are connected to you (incoming) and try to count how many of them are "spy nodes" because last time I did that (not running core) I was spammed with at least 10 of them that kept coming and going and sometimes changing their IP address too.

What are spy nodes ? I have never heard of them. Do they posses any risks and what is their purpose of connecting to our node?
I tried to get some info on it by googling and searching on the forum but couldn't find any.
I am able to get the peer info from the command 'getpeerinfo' but how do I identify if a node is spy node or a genuine one.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10549



View Profile
September 28, 2021, 04:01:30 AM
Merited by ABCbits (2)
 #7

What are spy nodes ? I have never heard of them. Do they posses any risks and what is their purpose of connecting to our node?
Spy nodes are clients that usually aren't actual full nodes (they can be). They usually don't even have a blockchain and only fake it. These clients connect to different full nodes to literary spy on them. Although it is not always malicious and sometimes they are just gathering statistics (like web crawlers).

For example one goal could be to find a link between a transaction and an IP address. The spy node connects to as many nodes as it can at the same time and if it sees tx1 coming from IPx for the first time then (some time later) sees tx2 spending outputs of tx1 and coming from same IPx and so on it can eventually conclude that addresses a, b, c, d belong to IPx and from there it could be possible to link IPx to the person's identity hence deanonymizing transactions.

The only risk is privacy risk (although I should add that there are a lot of good work done by core team to make such attempts as hard as possible), and of course wasting your resources.

I am able to get the peer info from the command 'getpeerinfo' but how do I identify if a node is spy node or a genuine one.
That's hard to say since I'm not running core but the simplest behavior they have which makes identifying some of them trivial are:
- One of them is literary called "snoopy" (the client name in version message)
- They can't reply to getdata, getblock, getheader, etc. since they don't have any blockchain
- The version message some of them use during handshake is buggy and if you send them a false block height they start advertising that!
- Some of them keep coming and going (they don't remain connected)
- They also don't ask for same things a normal node would such as checking their headers with you first to sync

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!