4 ms·
Just take care. Port forwarding is perfectly valid, and sometimes the only practical way to do things. But: - only open/forward the ports you need. - only exp
by drpixie 4y ago
Just take care. Port forwarding is perfectly valid, and sometimes the only practical way to do things. But:
- only open/forward the ports you need.
- only expose ports that use appropriate security - try to avoid plain-text, NEVER use easy to guess passwords; prefer encrypted sessions and properly secured logins (eg. ssh keys).
- be very aware of what is listening on the open ports. Some Windows ports expose dangerous services, and/or do so without authentication!
( Really, we shouldn't need firewalls because there should be NO dangerous services exposed on any machine. But older boxes were so full of problems that firewalls became the default way to manage the situation ... "we don't know what services to enable/disable, and they'll get re-enabled on the next OS update!@!, so we'll default to blocking everything using a firewall. )
- update, update, update. It seems like almost all code is broken. It's just a question of how badly, so it's very important to keep any exposed services up-to-date to limit the time you're exposed to know-bad software.
- you WILL be attacked - not personally but by the millions of bots randomly trying addresses/ports and guessing ids/passwords. Something like fail2ban is useful to discourage such attacks, but you WILL be attacked and MUST be prepared for it.
- monitor the machine - the scourge of the interwebs is boxes sitting out there sending spam and/or performing DOS attacks because the owner doesn't keep an eye on them !%@$!#@$!!
- pkdpic 4y agothis is all extremely helpful thank you so much for taking the time to write it all out!