7 ms·
It's crazy how fast people start attacking your infrastructure on the Internet these days. I recently started announcing one of my /23 subnets (512 addresses) o
by ThePhysicist 2y ago
It's crazy how fast people start attacking your infrastructure on the Internet these days. I recently started announcing one of my /23 subnets (512 addresses) over BGP for an anycast setup, once the route was announced and traffic flowing to the router tcpdump blew up with port scan activity on all IPs of the range. Of course that doesn't have anything to do with the route, it's just that tons of people seem to indiscriminately and continuously scan for open ports on all IP ranges (my range has been unannounced for many years before so it wasn't on someones list of active servers).
I find it a shocking that people still expose internal web services (e.g. Gitlab) openly to the Internet, in my opinion you should at least have one additional layer of protection through a VPN or similar mechanism so that your services aren't discoverable from the public Internet.
I only expose SSH from a single bastion host, which is the only host that's publicly reachable, something that I'd like to get rid off in the future as well by adding a VPN layer on top.
- jcalvinowens 2y ago> something that I'd like to get rid off in the future as well by adding a VPN layer on top. What VPN software would you use? Personally I've never found anything I consider as trustworthy as OpenSSH.
- throwaway63467 2y agoI use OpenVPN for historical reasons but today I’d go for Wireguard, much simpler, faster and integrated in the kernel, connectionless so much less friction when e.g. rebooting or changing networks.
- com 2y agoWireguard is quite good too, and if you’re up for some complication in your life you can do full mesh quite easily with it if your online infra is a bit distributed.
- RGamma 2y agoThere's also helpers for wireguard meshes. Or become dependent on yet another service like tailscale (at least there's headscale) or zerotier.
- running101 2y agoIt has no dhcp
- Sammi 2y agoAren't the cool kids using https://tailscale.com/ https://tailscale.com/ these days?
- diggan 2y agoAin't no cool kids (in my world) using centralized for-profit services for essential things like that.
- crote 2y agoPretty much all of it is open-source, and there's a self-hosted open-source alternative available for the only closed-source cloud-hosted component[0] - and that's even actively being promoted by Tailscale![1] [0]: https://headscale.net/ https://headscale.net/ [1]: https://tailscale.com/opensource#encouraging-headscale https://tailscale.com/opensource#encouraging-headscale
- diggan 2y agoSeems the cool kids are using Headscale then if anything, rather than Tailscale :)
- WhyNotHugo 2y agomulticast/mDNS is broken, and it doesn't seem that it will be fixed anytime soon. This prevents hosts discovering each other as if they were on non-virtual LAN. Personally, I find that having to set up an OIDC provider is too much overhead for a VPN. In a corporate setting, you likely have something already, but for individuals or small teams it's too much extra work.
- iudqnolq 2y agoHow could that work with their architecture? They configure your device to use a DNS server running locally in their app. That resolves their device names to their internal device IP addresses. Their device names default to hostnames, just like mDNS does. So to give an example if I enter http://geder http://geder in my browser I want that to resolve to 100.100.5.10 regardless of if I am on my home network (where geder is) or if I am on a train. From my perspective half the reason to use tailscale is that it replaces why I'd want mDNS with less bugs.
- imhoguy 2y agoWireguard. Actually I setup also 2nd backup tunnel in case some upgrade or change messes up the first one.
- tmdetect 2y ago+1 to WireGuard. For people new to it, there are some great scripts which set up and configure it for you like https://github.com/Nyr/wireguard-install https://github.com/Nyr/wireguard-install
- RGamma 2y agoYep, don't ever put up badly configured public SSH. It's gonna be pwned in literal seconds. The net increasingly feels like what's going on behind Cyberpunk's blackwall.
- itsTyrion 2y ago> literal seconds Under what condition, the root pw being "admin"?
- arnavpraneet 2y agoway more common than you think
- _nalply 2y agoOne really never can be sure but I do this and I hope it is enough: - put ssh on a port not 22 - only allow key-based logins - don't allow root logins - keep software up to date Not that I am an expert... So please tell me if I have a hole somewhere in my setup.
- immibis 2y agoIt's defense-in-depth. Really, all you need is: - don't have a guessable password With extremely rare exceptions (the NSA might), attackers don't have some magic sauce that breaks SSH. Even the recent SSH vulnerability was very hard to actually exploit (but you should have updated ASAP anyway). Their strength is that they just guess passwords all day long on the whole internet. If one server has "admin", or "root", or "1234", they'll get in instantly. If one server has "alcatrazquinine" they'll get in less instantly. If one server has "XgMTaJR35a7gSpXTD2T", they won't ever get in. This is secure from all the people scanning ssh keys. Well, don't use that exact password I just published. Key authentication is preferred for two reasons. One is that if you accidentally connect to the wrong server you won't transmit your password to that server. The other is that you can store your key in a file and use it automatically so that just typing "ssh myserver" gets you all the way to a shell prompt. That's very convenient. Not allowing root logins can make sense for auditing reasons (so you can see which user logged in and then used sudo), but if this is just your private server, there isn't really much reason to avoid it. If it makes you feel better, just pretend your name is "root". It also makes sense if you subscribe to the philosophy of "typing sudo in front of every command helps prevent mistakes," which I don't. Using a port other than 22 can remove provide a very slight decrease in bandwidth and CPU load, and a bigger decrease in log file output, from processing failed logins by scanners. If these things actually matter to you, go ahead. I promise they don't. Doing it for security is either paranoia or security theater, depending on whether your password is "XgMTaJR35a7gSpXTD2T" or "1234". Keeping software up to date: of course.
- BlueTemplar 2y agoThis sounds to be an issue specific to IPv4 - wouldn't going IPv6-only make IP scanning impractical for bad actors ?
- sulandor 2y agoyes, but not impossible and it comes with other problems
- kachapopopow 2y agoYou still have to announce your used ranges, so unless you announce /64's it's pretty much the same thing.
- bauruine 2y agoMost ISPs don't allow BGP announcements smaller than /48 so you don't get any usefull information from that.
- ThePhysicist 2y agoBut the smallest range you can announce is /48, that's still way too vast to scan completely.
- bauruine 2y agoYes it's only IPv4 where it's practical to scan the whole address space in minutes but there are methods to find IPv6 addresses [0] certificate transpareny logs are also scanned for hostnames to get AAAA records. But from my experience it's multiple orders of magnitude less than v4. [0]: http://netpatterns.blogspot.com/2016/01/the-rising-sophistication-of-network.html http://netpatterns.blogspot.com/2016/01/the-rising-sophistic...
- Dylan16807 2y agoDepends on how many people are using random-ish addresses and how many are using ::2 and friends.
- ThePhysicist 2y agoI'd love to switch everything to IPv6, but reachability is not yet there, I estimate it will be another 10 years with the current rate of adoption.
- gmuslera 2y ago"These days"? 25+ years ago it was pretty common to get scripts/bots checking your exposed web servers all time (I mean, it was a pretty frequent appearence in web access logs) and turning on firewall rejected access log gave you a permanent traffic of attempts for a lot of known and unknown ports. If you will expose something (even some deep hidden web component) make sure that it is not a door to your data and infrastructure. What had changed a bit since then is from where that traffic comes, and deciding if its right to receive/block it or not. Legal servers/services, end user side proxies, cloud providers, the amount of crawlers had increased a lot, and so on.
- z3t4 2y agoI often test web sites on some random port before going live, and at times the customer calls and say "nice work" because they have found their site in Google search. So one of the biggest source for these scans are Google crawlers. I know I shouln't do that, and I'm not complaining... Within seconds after putting a site up on a random port you get scans, mostly for Wordpress exploits. Some companies will instantly put your IP in their firewall block list if you attempt to access an uncommon port, so be careful if you still surf the web via telnet.
- osigurdson 2y agoIf one self hosts a VPN, are there any security benefits over properly configured SSH? I assume you must have to have an IP address somewhere. Bad guys will be scanning that I assume. If the key is to use a managed VPN service, what magic are they adding? Legitimate question. I assume there might be a benefit, I'm just not sure what it is.
- nine_k 2y agoIt depends, I think, on the complexity of the VPN. SSH allows to do so many things, has so many config options. To the opposite, Wireguard is very simple, allows basically one thing (authenticate by a key, then pass packets), and is much harder to misconfigure. (OpenVPN, on the other hand, does not have this advantage.)
- osigurdson 2y agoIf true, interesting that it all comes down to likelihood of misconfiguration. However, I can't see anything fundamental that a VPN adds either. I wonder, if there was an ssh that couldn't be configured incorrectly and also had a little "anti-hack" tech built in (e.g. disallow more than N connection attempts per minute, etc., what ever is normally done).
- nine_k 2y agoAfter authnz, SSH runs a shell (or other specified remote program), while Wireguard just sets up a network interface. I think it's really hard to make Wireguard run something remotely as you connect, AFAICT. You can achieve a somehow similar result running by OpenSSH as `ssh -N -D`: do not run anything on the remote end, work as a socks5 proxy.
- immibis 2y agossh -w sets up a network interface ssh -w -N sets up a network interface and does not run a shell It still runs over TCP, so it's not ideal. TCP-over-TCP is a recognized antipattern that causes extra retransmissions, wasted bandwidth and delays.
- immibis 2y agoAlternatively, recalibrate your expectations. A port scan is nothing, hardly even qualifies as an attack. It's Internet background radiation. You want to go to space, there's background radiation in space, you want to go on the Internet, there's background radiation on the Internet. And if you aren't running vulnerable services, this port scanning radiation is equivalent of eating another banana per month. It only bothers you because you're looking directly at it in your console. If you bring an overly sensitive Geiger counter on your aeroplane ride, you might be alarmed, but if you're not aware of it, it won't hurt you at all. I am also surprised by internal services being exposed to the internet, but that's for two reasons: (1) I don't trust most programs' authentication systems, and (2) I don't want people to know which services I'm using internally - not from a technical security standpoint, but sometimes just privacy. But things that are supposed to be on the Internet, that I trust to have a strong front door (or be suitably sandboxed) - they can be on the Internet all day. Port scanning is just the Internet equivalent of walking around the city taking notes on whose lights are on. Stalkerish? Maybe a bit. But it's public info. By the way: ssh -w makes a VPN tunnel interface, but it won't auto-configure the rest of the VPN like actual VPN products do.