Accessible CoAP Report

This report identifies devices that have an accessible CoAP (Constrained Application Protocol) on port 5683/UDP. CoAP is a specialized web transfer protocol for use with constrained nodes and constrained networks. As described in RFC 7252, it is designed for machine-to-machine (M2M) applications such as smart energy and building automation.

Exposed CoAP services can be used as reflectors in DDoS amplification attacks. They can also leak information (including authentication credentials), and in some cases may potentially allow for remote manipulation of exposed devices and associated services.

This report was enabled as part of the European Union INEA CEF VARIoT project.


Fields

  • timestamp
    Time that the IP was probed in UTC+0
  • ip
    The IP address of the device in question
  • protocol
    Protocol that the CoAP response came on (always UDP)
  • port
    Port that the CoAP response came from (usually 5683)
  • hostname
    Reverse DNS name of the device in question
  • tag
    Set to coap
  • asn
    ASN of where the device in question resides
  • geo
    Country where the device in question resides
  • region
    State / Province / Administrative region where the device in question resides
  • city
    City in which the device in question resides
  • naics
    North American Industry Classification System Code
  • response
    Blob of the decoded CoAP response to the resource discovery probe. This should typically be in the CoRE Link Format as described in RFC6690.

Sample

"timestamp","ip","protocol","port","hostname","tag","asn","geo","region","city","naics","sic","response"
"2020-06-20 01:21:27","192.0.2.5","udp",5683,"dsl.192.0.2.0.pldt.net","coap",9299,"PH","NUEVA ECIJA","DEL PILAR",517311,,";title=""General Info"";ct=0,;title=qlink/searchfh,;title=qlink/searchgw,;title=qlink/request,;title=qlink/success,;title=device/inform/bootstrap,;title=device/inform/boot,;title=device/inform/syncreq,;title=device/inform/offline,;title=device/inform/heartbeat,;title=device/inform/data,;ct=0"
"2020-06-20 01:21:27","192.0.2.10","udp",5683,"192.0.2.10.static.pldt.net","coap",9299,"PH","MANILA","MANILA",517311,,";title=""General Info"";ct=0,;title=qlink/searchfh,;title=qlink/searchgw,;title=qlink/request,;title=qlink/success,;title=device/inform/bootstrap,;title=device/inform/boot,;title=device/inform/syncreq,;title=device/inform/offline,;title=device/inform/heartbeat,;title=device/inform/data,;ct=0"
"2020-06-20 01:21:27","198.51.100.77","udp",5683,,"coap",38917,"RU","IVANOVSKAYA OBLAST","IVANOVO",0,,",,,,,,,"
"2020-06-20 01:21:27","203.0.113.111","udp",5683,"dsl.203.0.113.0.pldt.net","coap",9299,"PH","LANAO DEL NORTE","BUNAWAN",517311,,";title=""General Info"";ct=0,;title=qlink/searchfh,;title=qlink/searchgw,;title=qlink/request,;title=qlink/success,;title=device/inform/bootstrap,;title=device/inform/boot,;title=device/inform/syncreq,;title=device/inform/offline,;title=device/inform/heartbeat,;title=device/inform/data,;ct=0"
"2020-06-20 01:21:27","203.0.113.55","udp",5683,,"coap",9808,"CN","JIANGXI SHENG","NANCHANG",517312,,",;title=""Qlink-ACK Resource"",;title=""Qlink-Request Resource"",;title=""SearchGW Resource"",;title=""Qlink-Success Resource"",;title=""Qlink-WLAN Resource"",,,;title=""Connect To Diagnotor"",;title=""Inform Data Resource"",;title=""config-properties Resource"",,;title=""Qlink-Regist Resource"",;title=""Qlink-SHOW Resource"",,,;title=""Device Control Resource"",;title=""Control Data Resource"",,;title=""Boot-Request Resource"",;title=""bootstrap-Request Resource"",;obs;title=""Inform Data Resource"",;title=""HeartBeat Resource"",;title=""ChildDevice Offline Resource"","
"2020-06-20 01:21:27","203.0.113.240","udp",5683,,"coap",56046,"CN","JIANGSU SHENG","YANGZHOU",517312,,",;title=""Qlink-ACK Resource"",;title=""Qlink-Request Resource"",;title=""SearchGW Resource"",;title=""Qlink-Success Resource"",;title=""Qlink-WLAN Resource"",,,;title=""Connect To Diagnotor"",;title=""Inform Data Resource"",,;title=""Basic-heartbeat Resource"",;title=""Qlink-Regist Resource"",;title=""Qlink-SHOW Resource"",,,;title=""Device Control Resource"",;title=""Control Data Resource"",,;title=""Boot-Request Resource"",;title=""bootstrap-Request Resource"",;obs;title=""Inform Data Resource"",;title=""HeartBeat Resource"",;title=""ChildDevice Offline Resource"","

Our 80 Report Types