logoalt Hacker News

vbernat • today at 4:26 AM • 1 reply • view on HN

The attack you mention is solved in the second part of the article.


Replies

jamiesonbecker • today at 4:43 AM

I did notice that you tried to mitigate the risk, but why not just pick a high port rather than this complex redirection?

Your scheme is smart and creative but unnecessarily risky.

SSH can do remote listens to the world by itself, no second nginx needed, but sish or ngrok might be a better solution for the general case.

Anytime you punch holes, you're taking a risk, so make it as narrow as you can.

➕ show 1 reply