5 ms·
I tried using `tailscale funnel` against a dummy server `python -m http.server`, and within 10 seconds the bots started to check for vulnerabilities. Tailscale
by abdusco 1y ago
I tried using `tailscale funnel` against a dummy server `python -m http.server`, and within 10 seconds the bots started to check for vulnerabilities.
Tailscale warns you about how enabling it will issue an HTTPS certificate which will be in a public ledger. But I wasn't expecting it to be this quick.
127.0.0.1 - - [10/Aug/2025 00:11:34] "GET /@vite/env HTTP/1.1" 404 -
127.0.0.1 - - [10/Aug/2025 00:11:34] code 404, message File not found
127.0.0.1 - - [10/Aug/2025 00:11:34] "GET /actuator/env HTTP/1.1" 404 -
127.0.0.1 - - [10/Aug/2025 00:11:34] code 404, message File not found
127.0.0.1 - - [10/Aug/2025 00:11:34] "GET /server HTTP/1.1" 404 -
127.0.0.1 - - [10/Aug/2025 00:11:35] code 404, message File not found
127.0.0.1 - - [10/Aug/2025 00:11:35] "GET /.vscode/sftp.json HTTP/1.1" 404 -
127.0.0.1 - - [10/Aug/2025 00:11:35] code 404, message File not found
127.0.0.1 - - [10/Aug/2025 00:11:39] "GET /s/7333e2433323e20343e2538313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1" 404 -
- mh- 1y agoYeah, I have mixed feelings about CT (certificate transparency) for this reason. Folks are just consuming the firehose and scanning. And in this case, if the thing you're funnel'ing is on your residential connection, it basically amounts to you summoning a DDoS. One (obvious?) tip I'd offer is to put your stuff on high non-standard ports if you can. It'll reduce the amount of connections you get dramatically.
- modernpacifist 1y agoA DoS that will disappear once you close the funnel. Tailscale are proxying the traffic so your public IP isn’t exposed. Your choice of port makes no difference.
- tptacek 1y agoWhen you care about this, if you're managing your own certificates, you can issue wildcard certificates.
- mh- 1y agoHmm, yeah, that's a great suggestion, thanks!
- lysp 1y agoAlso serve the default website (via IP) from a basically empty self-signed certificate that doesn't give away any domain names or owner details.
- watermelon0 1y agoYou don't have to serve any certificates on the default website. Web server would just fail TLS connection, since it doesn't have a certificate for it. Not sure if this applies to all web servers, but at least Caddy and a few others support this.
- rendx 1y agoEven without CT, services on standard ports will quickly be discovered on IPv4. > On a computer with a gigabit connection, ZMap can scan the entire public IPv4 address space on a single port in under 45 minutes.
- straight-shoota 1y agoThis may discover services, but not hostnames. If the server does not disclose them (e.g. in the certificate used on the IP host), an attacker doesn't have much further to go on.
- gitgud 1y agoWait, so bots watch for new records added to this HTTPS cert public ledger, then immediately start attacking? To me that sounds like enabling HTTPS is actually a risk here…
- yjftsjthsd-h 1y agoThe server was already exposed. All this does is remove obscurity
- afavour 1y agoWhich is something that makes a notable difference. It’s telling the bots the OP listed are trying Vite endpoints, they’re targeting folks doing short term local web development. Removing obscurity and indicating relative likelihood of still being online is a big shift.
- dijit 1y agoI wish this trend of “security through obscurity” should mean that all info should just be exposed would die, its silly and lacks basis in reality. Even within infosec, certain types of information disclosure are considered security problems. Leaking signed up user information or even inodes on the drives can lead to PCI-DSS failures. Why is broadcasting your records treated differently? Because people would find the information eventually if they scanned the whole internet? Even then they might not due to SNI; so this is actually giving critical information necessary for an attack to attackers.
- augusto-moura 1y agoThe issue is not that obscurity per se is bad, but relying _only_ on obscurity is absolute the same as not having any security measures at all. With the public ledger or not, you will still need to implement proper security measures. So it shouldn't matter if your address is public or not, in fact making it public raises the awareness for the problem. That's the argument.
- 1y ago
- Jnr 1y agoI use Headscale, an open source implementation of Tailscale control server. And it doesn't have funnel functionality implemented out of the box, but I use a custom Traefik proxy manager Web UI in which I can expose ports on different Tailnet nodes. In order to avoid exposing something unnecessarily in the certificate transparency logs, I use a single wildcard certificate, so all the subdomains are not listed anywhere automatically. I use the same approach for services hosted in the internal subdomain, because I don't want everyone to know what exactly I'm running in my homelab.
- j45 1y agoAnother approach I’ve seen is to route public access from Traefik/nginx through a single Cloudflare tunnel instead, and Tailscale/Headscale can be left for private network and server access. The traefik box can have the single Cloudflare tunnel , and tailscsle can hang out behind the scenes. This way tailscale funnel doesn’t need to be public. There is the self hosted Cloudflare alternative that’s escaping my mind right now too.
- Jnr 1y agoCloudflare also issues certs and logs them in transparency logs. If you do not create a wildcard cert in Cloudflare, your subdomains will leak. And Cloudflare offers free wildcard certs only on the domain root.
- j45 1y agoAppreciate this super valid consideration. If services are being exposed for friends and family, using cloudflare tunnels might be a trade off between security or convenience. If the goal is to ensure security of a home lab online, the less of it that’s discoverable by automated bots, etc, the better.
- 0xCMP 1y agoI don't see why people don't just run their own CAs more for private stuff. If exposed for others I think the wildcard cert is also what I did, but most tutorials have you issuing certs via ACME for internal or local-only things which doesn't even need to happen. I personally run my own CA and even setup an ACME server and internal DNS. Nobody knows what I am doing there.
- nyrikki 1y agoIt was common to set up your own CA at one point, especially when DNS management was more manual, However it presented a huge attack surface and was challenging to manage. A compromised private CA can lead to widespread breaches, affecting various systems and applications that rely on its certificates. The CAB forum working groups being explicitly prohibited from working on private networks (at least historically) and market incentives also produced a situation where you can't really reduce the blast radius. ECS1 attacks on AD CS is probably the best publicly documented case for further research. The happy path is often manageable, but still complex, bland any mistake will result in huge risks.
- maccard 1y agoFor me, the value proposition isn’t there. I can get a wildcard domain signed from let’s encrypt and it works out of the box on every device, and you don’t have to deal with the fact that some/many appps will ignore your OS certificate rules.
- exac 1y agoAll the dev servers I've used over the past 10 years come with warnings that they're not security hardened, so I'd be wary of using `tailscale funnel` even though it is awesome to share like that so easily.