Showing posts with label Pi-Star security vulnerability. Show all posts
Showing posts with label Pi-Star security vulnerability. Show all posts

Pi-star security consideration

The Universal Plug-and-Play service is scary as heck! I always disable it on any devices I have connected to my network for exactly the reason Martin ran into.

Many people don't understand what the difference is between the Public and Private options in Pi-Star. The fact that Pi-Star is poorly documented is a big part of the reason for that.

I only have DMR enabled on my Pi-Star hotspots and I have 4 different sets of Public/Private radio buttons. Each one performs a separate function. With the exception of the Public/Private radio buttons for "Node Type", the rest are for automatically modifying the firewall policy on Pi-Star and controlling the UPNP commands that are sent to your firewall/router. Pi-Star runs a built-in host-based firewall called "iptables" which is the de-facto firewall in most Linux distributions.

Pi-star Captive Portal default remote password

Pi-star Captive Portal default remote password



The default Pi-star Captive Portal remote password is in Configuration <-> Expert <-> ircDDBGateway <-> at the end of the page and is In the remote password field.

Pi-star Captive Portal default remote password

Pi-star security vulnerability

My Jumbospot based hotspot had been running continuously for weeks without problems, then I noticed that it had begun hanging most nights. This carried on for a couple of weeks with me trying out various configuration changes without success. Then I logged in via SSH one evening and got a "disk full" error message referring to "/var/log". When I checked, I found that the "auth.log" file had grown to fill the entire "/var/log" partition. Viewing it revealed that my hotspot was under continual attack from the internet - bots around the world were flooding it with login attempts with random user ids and passwords on a range of port numbers and protocols!

Pi-Star security vulnerability

... have you opened it up to the outside world?

My Jumbospot based hotspot had been running continuously for weeks without problems, then I noticed that it had begun hanging most nights. This carried on for a couple of weeks with me trying out various configuration changes without success. Then I logged in via SSH one evening and got a "disk full" error message referring to "/var/log". When I checked, I found that the "auth.log" file had grown to fill the entire "/var/log" partition. Viewing it revealed that my hotspot was under continual attack from the internet - bots around the world were flooding it with login attempts with random user ids and passwords on a range of port numbers and protocols!