3 ms·
Your opening question seems to be specifically asking about the web interface — but each and every exposed service is a potential vulnerability, so if PiHole's
by jimsmart 6y ago
Your opening question seems to be specifically asking about the web interface — but each and every exposed service is a potential vulnerability, so if PiHole's DNS server is also exposed as well as the admin interface, then that is effectively another open port, running a PiHole-customised version of dnsmasq — which is certainly more surface area to a potential attacker.
DNS is no better or worse than any other service that is exposed, if it is found to be vulnerable to an exploit. If an exposed service is vulnerable, it's vulnerable.
- podiki 6y agoYes, I was thinking just the admin interface with it's DNS not listening to the outside internet. What I see as the biggest risk (other than from other exploits for any web service) is that an attacker could change where DNS queries are directed after Pi Hole. So instead of e.g. Cloudflare's DNS it goes to an attacker controlled DNS. Of course there are plenty of details, but my question was just broad strokes: is having your DNS changed for your network (or whatever else you think one can do with access to the admin panel) a huge risk? The scale could be 1 (say your router responds to port requests with denial rather than silently timing out) to 10 (you turned on ssh with root access and no password set).
- jimsmart 6y agoYour threat vector seems very specific. You are still talking about “biggest risk”. But without doing a proper risk analysis, for each individual case, this is just wasted speculation and a pointless conversation. If someone exploits a vulnerability, particularly if they gain root access, all bets are off, doesn’t matter the service.
- jimsmart 6y ago> Is having DNS changed for your network a huge risk? Yes, of course. An attacker can now effectively serve malware of their choosing, to network clients of their choosing.