| ▲ | jamiesonbecker 7 hours ago | ||||||||||||||||
This is wildly over-complicated and also has a bunch of footguns and security risks. For example, that very first NGINX section allows an attacker to direct their incoming traffic to any arbitrary listening port on localhost. They can even write a simple for loop in bash that would use curl to test all of the different ports. This also bypasses any firewall rules that you might have blocking traffic from the outside world. be very careful following the instructions in this article. Read the man page for SSH, and especially the remote forward section. https://man7.org/linux/man-pages/man1/ssh.1.html | |||||||||||||||||
| ▲ | vbernat 6 hours ago | parent | next [-] | ||||||||||||||||
The attack you mention is solved in the second part of the article. | |||||||||||||||||
| |||||||||||||||||
| ▲ | zac-builds 23 minutes ago | parent | prev [-] | ||||||||||||||||
[flagged] | |||||||||||||||||