EDIT 2:
Just provided instructions in the repo for how to configure DDNS: https://github.com/IAmStoxe/wirehole#configuring-for-dynamic...
Also modified it so only the port 51820 is exposed preventing any unintentional exposure.
EDIT 2:
Just provided instructions in the repo for how to configure DDNS: https://github.com/IAmStoxe/wirehole#configuring-for-dynamic...
Also modified it so only the port 51820 is exposed preventing any unintentional exposure.
> Either specify both ports (HOST:CONTAINER), or just the container port (an ephemeral host port is chosen).
It sounds like you get a random publicly accessible port unless you specify a non publicly accessible IP. I'm not sure whether having a DNS server listening on a non standard port would be an issue though.
but nonetheless you're ingress rules in your cloud provider will not allow anything but that's single port so it's not really a big deal provided you close everything else off in your firewall.
I will make an update to see how I can work around this
That's all that's required for a DNS amplification attack. :)