Protection & security

Unknown names and IPs in your server logs: are you being hacked?

Quele, Founder of BlackProtectUpdated 6 October 20265 min read
In short

Unknown names that connect briefly and disconnect right away almost always come from scanner bots. They sweep the whole internet for Minecraft servers and check whether they can get in without a whitelist.

It's not a hack. But open servers end up on lists that griefers use too. Keep the whitelist on, let accounts be verified (online-mode=true) and keep your real IP hidden.

Contents
  1. What you see in the logs
  2. What scanner bots want
  3. How to protect yourself
  4. Frequently asked questions

What you see in the logs

Typical lines look like this, often in the middle of the night and with changing ports:

log
[23:52:14] [Server thread/INFO]: Scanner123 (/203.0.113.7:38802) lost connection: Disconnected
[01:16:57] [Server thread/INFO]: Scanner123 (/203.0.113.7:54948) lost connection: Disconnected

The name is usually a program's name, not a person. The IP often belongs to a rented server in a datacenter. The port changing every time is normal: every connection gets a new one.

What scanner bots want

There are programs that probe every address on the internet for Minecraft servers around the clock. They first query the server list (version, players, MOTD) and then often try to join to find out whether a whitelist is on.

  • Harmless: many only collect data for statistics or server search engines.
  • Not harmless: others build lists of servers without a whitelist. Such lists have been used for mass griefing before.

If your log says “lost connection” but never “joined the game”, the whitelist did its job. Nobody was on your server.

How to protect yourself

  1. Whitelist for private servers

    If only a fixed group plays, keep the whitelist on permanently: /whitelist on and /whitelist add <name>.

  2. Let accounts be verified

    If server.properties says online-mode=false, anyone can join under any name – including yours. Switch to online-mode=true if at all possible, or use a login plugin.

  3. No permissions for strangers

    Give OP only to real team members and check which plugins open commands to everyone.

  4. Hide the real IP

    Scanners find servers by IP address. If your server sits behind BlackProtect, our filter only answers when someone uses your domain. Anyone just trying addresses won't find your server there. For that to work, the real IP must not be public: Hide your server IP.

A word on changing the port

Moving from 25565 to another port slows simple scanners down briefly, but good scanners try other ports too. On its own it is not protection.

Frequently asked questions

Should I be worried?

If the logs only show “lost connection” and the whitelist is on: no. Nobody got in. Be worried if strangers actually “joined the game” or ran commands.

Should I ban the IP from the log?

You can, but it does little. Scanners change addresses constantly. Whitelist, account verification and a hidden server IP protect much better.

How do they know my server? I never published it.

They don't, not specifically. These programs simply try every address on the internet. Any server with an open port is found within hours.