Jump to content

Invite Scene - #1 to Buy, Sell, Trade or Find Free Torrent Invites

#1 TorrentInvites Community. Buy, Sell, Trade or Find Free Torrent Invites for Every Private Torrent Trackers. HDB, BTN, AOM, DB9, PTP, RED, MTV, EXIGO, FL, IPT, TVBZ, AB, BIB, TIK, EMP, FSC, GGN, KG, MTTP, TL, TTG, 32P, AHD, CHD, CG, OPS, TT, WIHD, BHD, U2 etc.

LOOKING FOR HIGH QUALITY SEEDBOX? EVOSEEDBOX.COM PROVIDES YOU BLAZING FAST & HIGH END SEEDBOXES | STARTING AT $5.00/MONTH!

MyAnonaMouse News


Recommended Posts

PSA - Make sure your client isn't open to the PUBLIC

We've been getting reports of a bunch of MAM users with clients wide open on the web with no Access Control to prevent anyone who discovers it from taking over the client.
Clients left open this way risk people using them to download things without permission, taking the files that have already been downloaded, or even the unauthorized user running code on your server itself.
Some of these clients are also running as root on linux, which means this opening to Remote Code Execution can be used to completely take over the system in question (not just the client or the user account the client is running as).
These security issues don't just put the specific user at risk, but everyone on the site, as it's a gateway to getting more peer info (via the client).

Everyone should verify that either all remote interfaces are turned off (for clients you only access locally) or appropriate measures to limit access are in place.
The bare minimum is setting a secure and complex password on the remote interfaces, but this alone isn't ideal as some don't have means to Ban on repeated Failure, leaving open brute forcing.
The means of better security will depend on the client and your setup, but can include also limiting source IP or range (if you always access from somewhere), securing web interfaces with ssl client certificate, or setting up something like Fail2Ban to block IPs on failures.

TL;DR
Users with Insecure Clients are putting themselves and us at risk.
We're sending messages as we get notified that they are open as well, but best you check first
 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Check out what our members are saying

  • Our picks

×
×
  • Create New...