5 ms·
There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the passw
by angott 5y ago
There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).
- toxicFork 5y agoAnd I'd bet a nice amount that most of them have the default passwords. Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.
- power78 5y agoAccording to a comment above, these routers require an admin password change when setup with no way around that.
- deleted 5y ago[deleted]
- toxicFork 5y agoSounds like they learned their lesson
- deleted 5y ago[deleted]
- MontrealRaised 5y agoThe ISP assigned a unique password and puts it as a label beneath the router - in my case. I kept it. I consider it save enough.
- iamcreasy 5y agoI was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?
- blacksmith_tb 5y agoIf it's a static site? Probably safe-ish, I suppose bots and bored teens could DDOS it. You could also choose a non-standard port, that might cut down on the noise.
- iamcreasy 5y agoThanks! I want to learn what could go wrong. Can you point me to any resource/book to study this particular matter?
- kube-system 5y agoIt depends entirely on what technologies you are specifically exposing. If you are serving a page with a web server application like Nginx or Apache, you should read about securing those applications. If you are writing a NodeJS application, you should read something specific to that. If you want something very general and comprehensive, you can read this, although it is probably too involved for a basic "website": https://owasp.org/www-project-web-security-testing-guide/stable/ https://owasp.org/www-project-web-security-testing-guide/sta...
- SturgeonsLaw 5y agoI would recommend you put it behind Cloudflare, it will mask your home IP address and will absorb any attacks https://skylar.tech/create-fast-websites-from-your-home-network-using-cloudflare/ https://skylar.tech/create-fast-websites-from-your-home-netw...
- southerntofu 5y agoPlease don't do that. It's a terrible idea because CloudFlare will then get to decide who gets to see your website or not (and CloudFlare hates privacy tech like Tor), and also because then CloudFlare will terminate the HTTPS (TLS) connection on their side so they essentially get to know all your passwords. I've selfhosted on 64Kbit/s modem then xDSL for years without a problem (apart from bots trying default passwords). If you are really afraid you'll run into DDOS attacks and whatnot, consider using a small 2-5$/mo VPS as reverse-proxy instead of CloudFlare to retain control of your infrastructure.