vletroye / SynoPackages

Various Synology Packages built with Mods Packager
126 stars 24 forks source link

MODS GateOne default port open to all #50

Open servlinux opened 2 years ago

servlinux commented 2 years ago

(BJr MR vletroye, MERCI de votre excellant travail!!) GateOne port open or accessible to all: I must admit this security is not your fault! The "Gateone" default package open or allow anybody from internet to open this port with "https://ipserver:8271". It is like to give internet a ssh and open all your internal SSH server to internet. Because GateOne have directly access to "local network". Anybody can use brute force or play at guessing game... Is it possible or do you have a way to block and not opening GateOne port and make it work only under DSM (kind of private/self proxy?? or 127.0.0.1:8271??) . So only user login on the NAS/DSM are authorised to use Gateone??

vletroye commented 2 years ago

Your IP is public ? Or don't you have a firewall to closes the access onto that port from internet ? As far as I am concerned, I don't forward anything (using port mapping) from internet to GateOne on my NAS.

I didn't try but maybe also possible to block in the NAS' firewall all incoming connection from other IP on that port...