Actions
tickets #160979
closedRe: Publicly exposed rsync (provo-downloadcontent.opensuse.org)
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
2024-05-27
Due date:
% Done:
0%
Estimated time:
Description
On 27/05/2024 09.28, cybersecurity SUSE wrote:
Dear Heroes of Opensuse,
Recently, a security finding has been found in opensuse infra, details
of which are given below:Security Finding:
RSYNC port (873) is found open without authentication controls.
IP : 91.193.113.71 Port: 873Recommended action:
Default rsync port to be blocked and RSYNC to be used with SSH
authentication.
This is the same machine as provo-mirror.opensuse.org
that is intended to offer public rsync so that mirrors can pull updates
from there.
IMHO it does not make much difference that we expose rsync on these IPs.
Encrypted public rsync transfers might be useful. I see that there is
rsync-ssl rsync://hostname/
using TCP port 874 for that.
Ciao
Bernhard M.
Files
Actions