LinHES Forums
http://forums.linhes.org/

what Apps are fairly secure without tunneling?
http://forums.linhes.org/viewtopic.php?f=5&t=17617
Page 1 of 1

Author:  jzigmyth [ Sat Jan 12, 2008 6:28 pm ]
Post subject:  what Apps are fairly secure without tunneling?

I just read the thread about a compromised Myth box. I'm wondering if having VNC enabled and running TightVNC viewer on the standard ports of 5800 and 5900 (Knoppmyth is behind a firewall with all other ports closed) would be considered too risky without tunneling?
Thanks,
Zig

Author:  mac [ Mon Jan 14, 2008 3:14 pm ]
Post subject: 

If you know that the address range that your going to reaching the box from you can
use iptables to limit access just the ranges you comming from.

There a number things to consider about the safty of an app.

- are you using strong passwords
- is the app using an encrypted channel

Many compromises come though webservers, mailservers and brute force attacks against weak accounts. ie. mythtv, mythtv.

Author:  graysky [ Tue Jan 15, 2008 2:53 pm ]
Post subject: 

Stick to ssh tunneling with strong passwords and 4k public/private keys in my opinion (stunnel is freeware for your win32/64 box). Otherwise don't forward the port on in your router.

Page 1 of 1 All times are UTC - 6 hours
Powered by phpBB® Forum Software © phpBB Group
http://www.phpbb.com/