[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Mldonkey-users] [Patch] Make HTTP-Realm configurable
From: |
Sergio Bayarri Gausi |
Subject: |
Re: [Mldonkey-users] [Patch] Make HTTP-Realm configurable |
Date: |
Tue, 17 Dec 2002 15:20:54 +0100 (MET) |
Hello,
> * Make the HTTP-Realm (shown when connecting to the web-interface)
> configurable in downloads.ini. Maybe im the only one so paranoid, but
> having my machine running 24/7 i dont want anybody scanning my
> interface-port to know im running mldonkey.
For security's sake, firewall your machine (iptables?) or adjust the
"allowed_ips" option in downloads.ini. It's quite easy to figure you're
running mldonkey otherwise: If port 4000 is open to everybody (as your
setup suggests) it will show a big:
"Welcome on mldonkey command-line"
When someone connects to it.
And even if you firewall your box, a simple scan is enough to know if
you're running mldonkey:
if (port 4080 open or firewalled) AND (port 4000 open or firewalled) AND
(port 4001 open or firewalled) then you're definitely running mldonkey.
I think that it's worse to have port 4000 open to everyone than to simply
show we're running mldonkey in the HTTP-Realm.
Greetings,
Sergio