5 ms·
I'm working on a personal project and not at all related to my work. I accidentally kept ports open :facepalm, sorting things out now :)
by pramodhs 6y ago
I'm working on a personal project and not at all related to my work. I accidentally kept ports open :facepalm, sorting things out now :)
- user5994461 6y agoRecommend to setup two subnets in your project. One public and one private. This prevents this sort of issues, instances in the private subnet simply don't get a public IP, they can't be reached over the internet. For reference, the standard practice in a company is to have a (third) separate subnet for databases, with zero internet access (no NAT gateway). Connection must be explicitly opened from/to database clients. It's a nightmare to manage on premise but it works really well in the cloud with firewalls allowing traffic based on instance tags.
- moooo99 6y ago> Recommend to setup two subnets in your project. One public and one private. This is very good advice. We recently had a uni project where we had to use a MongoDB database. Somebody just apt-get installed a mongodb onto a DO droplet called it a day. Two days later the only remaining records prompted us to transfer x amount of BTC to a adress that was store in our DB. It just contained dummy data, but it is worrying that something like this apparently happens to lots of companies as well. The only thing I find weird is that ElasticSearch itself does not offer a way to handle authentication, it was just enabled by a plugin that was paid (it seems like its free now).
- rovr138 6y agoRegarding elasticsearch, that’s actually fine. Just block access to it on your firewall to the public ports and require people SSH or VPN for access if needed. It’s not
- KMag 6y ago> The only thing I find weird is that ElasticSearch itself does not offer a way to handle authentication, it was just enabled by a plugin that was paid (it seems like its free now). "Wierd" is an interesting euphemism for "irresponsible." Defaults are very important. Insecure by default is insecure for 90+% of deployments.
- bigiain 6y agoI have _some_ sympathy for ElasticSearch and Redis, having designed/built their software under the assumption it isn't ever intended to be publicly accessible over the internet. I have a bunch of fairly important personal documents in a filing cabinet with no lock. And I'm perfectly fine with that. I wouldn't keep it in my front yard, because that's obviously stupid, but keeping it inside behind my locked door and upstairs in my office? A perfectly acceptable risk (for me and my files). I do agree that ElasticSearch do a quite poor/irresponsible job of pointing out their cabinet has no lock. I think Redis do a better job, but are seriously let down by all the internet tutorials that just say "sudo yum install redis" as a minor intermediate step in getting example-todo-list-de-jour working - without even a footnote explaining that anybody who actually visited the redis site now has instructions on how to p0wn your box. ( http://antirez.com/news/96 http://antirez.com/news/96 ) I do think the "Securing Redis" section of this page - https://redis.io/topics/quickstart https://redis.io/topics/quickstart - deserves to be much closer to the top - I'd have put it before the how to download/install/start instructions myself (though I _think_ recent versions of redis only bind to localhost in the default config, maybe?)
- dredmorbius 6y agoIf your assumptions are repearedly demonstrated invalid they are wrong. Change them.
- bigiain 6y agoPersonally, I reckon that applies at least as much (if not more) to the devs installing random software packages onto internet connected and un-firewalled servers - as it does to database developers who document clearly that their software is not intended and is actively unsafe to install on directly internet connected servers... Cave ne recipiens donum...
- dredmorbius 6y agoIf a thing should not be run in a given configuration then it should not be runnable in that configuration. The vendor / developer has both awareness and capability to ensure this.
- tgsovlerkhgsel 6y ago> Somebody just apt-get installed a mongodb onto a DO droplet called it a day. Two days later the only remaining records prompted us to transfer x amount of BTC to a adress that was store in our DB. If the default install does this, then I'd blame the package /distro maintainers. It should definitely at least only listen on localhost by default, with stern warnings what is going to happen if you change that without setting up proper security.
- mushi 6y agoMongoDB only binds to localhost for at least the last four versions (4+ years). Someone would have had to install a really old version or intentionally configure it to listen to public IP.
- mightyskull 6y agoElasticSearch does offer authentication. Most of our services were created like a POC & deployed to production, & I joined my company fairly recently. We had a planned release this week to secure ES. And Saturday, we got "meow"ed
- ramraj07 6y agoIssue is with AWS this setup instantaneously bumps the bill up from a few dollars a month to a few tens of dollars a month. Deal-breaker for personal projects. But, you can still secure the database with whitelisted IP addresses, which is what I do.
- duckmysick 6y agoWhere can I find a tutorial or a guide about it for, let's say, Ubuntu? Would this be a good start: https://www.digitalocean.com/docs/networking/vpc/how-to/enable/ https://www.digitalocean.com/docs/networking/vpc/how-to/enab...
- blaser-waffle 6y agoThe DO tutorial is a good start, but as another poster mentioned further down, check out: https://github.com/konstruktoid/hardening https://github.com/konstruktoid/hardening note: the DO tutorial will hold your hand a little; the hardening doc expects a (minor) degree of familiarity
- duckmysick 6y agoThanks. I saw this git repo earlier and it looks interesting (even though most of my machines are on LTS 18). I don't see anything about subnets in there though. Did I miss something?
- CloudNetworking 6y ago> It's a nightmare to manage on premise but it works really well in the cloud with firewalls allowing traffic based on instance tags. It's not though. Subnetting and firewalling are like the foundation of any corporate network.
- ljm 6y agoFirst thing I always do on any new VPS is to sort out SSH (disable root login, disable password login), set up fail2ban, install and configure ufw... and if I need to set up something like redis or similar, make sure it only listens to internal connections and also that it is decently auth'd. For deployment and other things I make users that can only write to certain directories; no sudo. It's nothing new or special but it gets lost in distributed systems. It's a lot more work when doing it in the cloud and spinning up these things from docker containers in K8S...but you're entirely to blame if you don't know what you're deploying and don't understand any of the potential threats.
- mkl 6y agoDo you know of any good resources for learning this stuff? I'm interested in being able to do this sort of thing on a small scale, but there seems to be an awful lot that I don't know I don't know.
- thrownblown 6y agohttps://github.com/konstruktoid/hardening https://github.com/konstruktoid/hardening What the parent post said is pretty much it in a nutshell, but I use that GitHub for basic Ubuntu server setup.
- KingOfCoders 6y agoWhen is didn't know better, I was always bitten by Docker circumventinging ufw.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]