5 ms·
The worst that could happen is the box running PiHole could get owned, and used as a stepping-stone towards hacking other devices on the network it is connected
by jimsmart 6y ago
The worst that could happen is the box running PiHole could get owned, and used as a stepping-stone towards hacking other devices on the network it is connected to, possibly without any obvious outward signs.
It's the same with any service exposed to the web really, that's pretty the bottom line.
- podiki 6y agoWhat I was trying to get at, is there anything special (worse?) with an exposed DNS related service over anything else? Is that inherently more risky than other services?
- jimsmart 6y agoYour opening question seems to be specifically asking about the web interface — but each and every exposed service is a potential vulnerability, so if PiHole's DNS server is also exposed as well as the admin interface, then that is effectively another open port, running a PiHole-customised version of dnsmasq — which is certainly more surface area to a potential attacker. DNS is no better or worse than any other service that is exposed, if it is found to be vulnerable to an exploit. If an exposed service is vulnerable, it's vulnerable.
- podiki 6y agoYes, I was thinking just the admin interface with it's DNS not listening to the outside internet. What I see as the biggest risk (other than from other exploits for any web service) is that an attacker could change where DNS queries are directed after Pi Hole. So instead of e.g. Cloudflare's DNS it goes to an attacker controlled DNS. Of course there are plenty of details, but my question was just broad strokes: is having your DNS changed for your network (or whatever else you think one can do with access to the admin panel) a huge risk? The scale could be 1 (say your router responds to port requests with denial rather than silently timing out) to 10 (you turned on ssh with root access and no password set).
- jimsmart 6y agoYour threat vector seems very specific. You are still talking about “biggest risk”. But without doing a proper risk analysis, for each individual case, this is just wasted speculation and a pointless conversation. If someone exploits a vulnerability, particularly if they gain root access, all bets are off, doesn’t matter the service.
- jimsmart 6y ago> Is having DNS changed for your network a huge risk? Yes, of course. An attacker can now effectively serve malware of their choosing, to network clients of their choosing.
- jimsmart 6y agoIf you are asking if the impact of having a DNS service hacked could be worse than any other service: there is no apples to apples comparison really. How can one measure what is 'worse': having one's DNS hacked vs any other service getting exploited? What data does the machine contain? What credentials does the machine provide? What networks are the machine connected to? How much 'value' does any of this data or network control have, or rather how much value would be lost if said data, device or network got hacked? The measure of all of these things is context specific, and depends entirely on the exact circumstances for each particular exposed device.