Hi,
yesterday I observed a very strange issue and I am not sure what I am looking at. Maybe a bug somewhere, maybe a fluke or maybe everything worked as expected:
I have several VMs which I start manually or via openhab rules when needed. In addition I monitor these VMs with the network binding and send notifications when they are up or down:
Thing:
network:pingdevice:Network_Wireguard [ hostname="vm1.domain.tld" ]
Item:
Switch Network_Wireguard_Active "Wireguard Server aktiv [MAP(network.map):%s]" (gNetwork, gSemNetworkWireguard) ["Status"] { channel="network:pingdevice:Network_Wireguard:online", stateDescription="" [readOnly=true], listWidget="widget:Netzwerkgeraet - List widget" [] }
Yesterday at around 5 in the morning I got a notification, that this VM had been started, which should not have been the case. I checked the VMWare log files and the the log files of the VM and indeed, it was not active at this time.
The openhab event log showed, that the item changed its state to ON and after one minute, which is the interval of the network binding checking these things, back to off. So I can rule out a bug in the rule sending the notifications:
2023-07-26 05:16:31.773 [INFO ] [openhab.event.ItemStateChangedEvent ] - Item 'Network_Wireguard_Active' changed from OFF to ON
...
2023-07-26 05:17:34.833 [INFO ] [openhab.event.ItemStateChangedEvent ] - Item 'Network_Wireguard_Active' changed from ON to OFF
There was nothing strange in the openhab log files.
So I am really not sure what happened there. It might have been someone hacking into my WLAN, but I highly doubt that. The access points are showing no unknown device, I am using a very long and purely random password and it would be very unlikely, that someone hacking into my WLAN uses the IP of this VM, which is outside of my DHCP range. Beside that, wo hacks a WLAN at this time und uses it for less than a minute?
I also checke the arp cache of my openhab server, wich showed the IP with a MAC address of 00:00:00:00, which is as expected.
For the time beeing I changed the logging of the network binding to Debug and scan my network with nmap every minute,
I would be very interested to know, if someone else noticed such a behavior or has any ideas what might have happened. I have never seen this before.
I am using the openHAB 4 release version on a Debian 12 server (via apt install) and Azul Java 17 in the lates version.
Thanks for your help,
Juelicher