5 ms·
If I'm reading the docker-compose file correctly, this creates an open dns resolver that is accessible to the outside, as Docker by default bypasses the firewal
by matrixagent 6y ago
If I'm reading the docker-compose file correctly, this creates an open dns resolver that is accessible to the outside, as Docker by default bypasses the firewall, see https://github.com/chaifeng/ufw-docker https://github.com/chaifeng/ufw-docker. I'm not quite sure about that, though, so I'd be happy to be corrected and learn more about how your setup works exactly.
- byteknight 6y agoEdit: I was wrong and I'm removing it to prevent spreading false information. Please see below. EDIT 2: Just provided instructions in the repo for how to configure DDNS: https://github.com/IAmStoxe/wirehole#configuring-for-dynamic-dns-ddns https://github.com/IAmStoxe/wirehole#configuring-for-dynamic... Also modified it so only the port 51820 is exposed preventing any unintentional exposure.
- matrixagent 6y agoAhh, so as long as I only list single ports and not pairs, it is not exposed to the host, because the other number of a pair is the port to be exposed on the host. And therefor it is not exposed to the public network in this case. Makes sense, thanks for the explanation!
- dsissitka 6y agoAre you sure? From https://docs.docker.com/compose/compose-file/ https://docs.docker.com/compose/compose-file/: > Either specify both ports (HOST:CONTAINER), or just the container port (an ephemeral host port is chosen). It sounds like you get a random publicly accessible port unless you specify a non publicly accessible IP. I'm not sure whether having a DNS server listening on a non standard port would be an issue though.
- deleted 6y ago[deleted]
- byteknight 6y agoSorry! I was wrong you are correct. but nonetheless you're ingress rules in your cloud provider will not allow anything but that's single port so it's not really a big deal provided you close everything else off in your firewall. I will make an update to see how I can work around this
- jradd 6y agoYou can try setting up a vpn and no tcp/udp is necessary. Pinhole could be accessed over local network.
- dsissitka 6y ago> but nonetheless you're ingress rules in your cloud provider will not allow anything but that's single port... That's all that's required for a DNS amplification attack. :)
- byteknight 6y agoThats not true. DNS isnt on 51820. That's wireguard. You cannot hit the DNS unless you're connected to the wireguard VPN provided you're using a cloud provider and you havent configured any additional ingress rules other than port 51820. That I am positive on.
- dsissitka 6y agoYou're right! I thought we were talking about the Pi-hole port. ><
- byteknight 6y agoModified it so that only port 51820 is exposed preventing any unintentional exposure.
- NerdyBird 6y agoThis is false. Not listing the host port will make docker choose a random one. It however is still opened up in the firewall by default. Source: https://docs.docker.com/compose/compose-file/#ports https://docs.docker.com/compose/compose-file/#ports
- byteknight 6y agohttps://news.ycombinator.com/reply?id=24426759&goto=item%3Fid%3D24425424%2324426759 https://news.ycombinator.com/reply?id=24426759&goto=item%3Fi...
- jradd 6y agoThat’s what he said