Closed Aldaviva closed 5 months ago
Hi,
Thanks for submitting this issue. I'll remove these servers from the automated checks straight away.
Just for my own curiosity, can you tell me more about the incorrect results returned by these services? Were they still within the range that was expected (e.g. 100.101.102.103 vs 100.101.102.104) or completely different?
I'm thinking that maybe what you observed was just a weird/interesting behaviour on the NAT part rather than anything to do with the STUN servers themselves. However, if that were the case, you'd see other services return wrong IP addresses too, which doesn't seem to be the case.
I have removed the two services from the candidates list. They will be removed from the valid lists at the next automated check in about 1h.
Thanks!
Here are the incorrect IP addresses they returned. My correct WAN IP address was in the 73.202.30.0/24
subnet at the time.
stun.bergophor.de:3478
192.168.80.67
(which is in a private range)stun.usfamily.net:3478
107.12.198.224
121.5.32.247
136.249.128.168
151.70.235.94
170.87.255.116
189.172.15.230
199.225.99.231
237.120.242.186
25.32.55.201
54.65.6.154
55.204.238.254
79.244.154.201
8.144.106.11
87.46.19.57
99.93.120.192
Okay, this is very strange, these IP addresses are all over the place.
Thanks again for spotting this!
Hello,
Thanks for providing this list.
When using random STUN servers from this list, I found that some of the servers returned incorrect public client IP addresses in response to binding test requests. The remaining hundreds of servers consistently return my correct public IP address, so I believe my STUN client is operating properly.
Servers that return incorrect results
stun.bergophor.de:3478
(87.129.12.229
)stun.usfamily.net:3478
(64.131.63.216
,64.131.63.217
)They returned 16 incorrect addresses over 8 days.
I see in the readme that you automatically check for a correct binding response before adding a server to the Valid lists, so I'm not sure if the incorrect behavior of these servers in intermittent, or maybe only appears for some users, or some other reason I haven't thought of.
I have blocked my client from using these two hostnames in STUN requests, but you may want to remove them from your candidate set to avoid causing problems for other users.
Thanks.