Jump to content

MyAnonaMouse News - Tracker News - InviteHawk - Your Only Source for Free Torrent Invites

Buy, Sell, Trade or Find Free Torrent Invites for Private Torrent Trackers Such As redacted, blutopia, losslessclub, femdomcult, filelist, Chdbits, Uhdbits, empornium, iptorrents, hdbits, gazellegames, animebytes, privatehd, myspleen, torrentleech, morethantv, bibliotik, alpharatio, blady, passthepopcorn, brokenstones, pornbay, cgpeers, cinemageddon, broadcasthenet, learnbits, torrentseeds, beyondhd, cinemaz, u2.dmhy, Karagarga, PTerclub, Nyaa.si, Polishtracker etc.

Please pay attention NOT TO DOUBLE POST!

MyAnonaMouse News


Eren
 Share

Recommended Posts

PSA - Make sure your client isn't open to the PUBLIC

We've been getting reports of a bunch of MAM users with clients wide open on the web with no Access Control to prevent anyone who discovers it from taking over the client.
Clients left open this way risk people using them to download things without permission, taking the files that have already been downloaded, or even the unauthorized user running code on your server itself.
Some of these clients are also running as root on linux, which means this opening to Remote Code Execution can be used to completely take over the system in question (not just the client or the user account the client is running as).
These security issues don't just put the specific user at risk, but everyone on the site, as it's a gateway to getting more peer info (via the client).

Everyone should verify that either all remote interfaces are turned off (for clients you only access locally) or appropriate measures to limit access are in place.
The bare minimum is setting a secure and complex password on the remote interfaces, but this alone isn't ideal as some don't have means to Ban on repeated Failure, leaving open brute forcing.
The means of better security will depend on the client and your setup, but can include also limiting source IP or range (if you always access from somewhere), securing web interfaces with ssl client certificate, or setting up something like Fail2Ban to block IPs on failures.

TL;DR
Users with Insecure Clients are putting themselves and us at risk.
We're sending messages as we get notified that they are open as well, but best you check first

  • Like 1
Link to comment
Share on other sites

Avoid unnecessary posts such as 'Thank you', 'Welcome', etc. Such posts will be deleted and user will be warned if it happens again. If caught spamming, the following actions are applicable -

  • First time - Warning
  • Second time - 5000 Points will be deducted
  • Third time - Ban for 7 days
  • Fourth time - Permanent Ban

If the post helped you, reward the user by reacting to the post like this -

download.png

 

Link to comment
Share on other sites

The last post in this topic was made more than 14 days ago. Only post in this topic if you have something valuable to add. Irrelevant posts are not allowed and you will be warned/banned for spamming old topics.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Read this before posting -
  • Only post if you have something valuable to contribute.
  • Avoid unnecessary posts such as 'Thank you', 'Welcome', etc. Such posts will be deleted and you will be warned if it happens again.
  • If the post helped you, reward the user by reacting to the post like this -                      1.jpg
Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Customer Reviews

  • Similar Topics

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.