5 ms·
> It is not sufficient security to only bind to 127.0.0.1 (the “loopback interface”) What would be a better, more secure thing to do when you have multiple web
by shurcooL 7y ago
> It is not sufficient security to only bind to 127.0.0.1 (the “loopback interface”)
What would be a better, more secure thing to do when you have multiple web servers on one machine behind a SSL-terminating reverse proxy?
- cosarara 7y agoThe thing to do is not run a web browser on that machine. Run the servers in a VM.
- notatoad 7y agoBut this seems to be able to see servers accessible to the local machine, so if my Dev server in a VM is accessible from my browser, it's accessible to any webpage in my browser?
- cosarara 7y agoThe reverse proxy is accessible from your browser and is properly configured to not accept random requests from any webpage (See: CORS). The others are not directly accessible, but only through the reverse proxy server. Does that make sense?
- notatoad 7y agonot really, no. i still don't see what the reverse proxy or the VM are bringing to the table here. If i'm understanding the necessary CORS config here, it's to simply not send any access-control-allow-origin header, which does not require a VM or reverse proxy, most HTTP services do that by default. simply being accessed through a reverse proxy instead of directly doesn't add any additional security
- cosarara 7y agoActually, you are right.