Do people out there really “allow any” ports on their firewalls? Or are those ports for control inside the firewall only?
Do people out there really “allow any” ports on their firewalls? Or are those ports for control inside the firewall only?
I'm playing around with IP address level detecting and blocking using incoming ports as indicators. I'm going to set aside some time to think more about restrictions on outgoing ports as a result of this and your comment.
Do some logging of frequently used remote ports over a couple of weeks and create a baseline set of allowed ports, block everything else and see what breaks.
I already use the limited Feodo Tracker[0] lists to flag in my firewall logs whether any device on the network has attempted to contact a known C&C IP address.
Thanks for push.
Devices reconfigured to NOT do that at all.
Now that's cleared, the log won't be quite so cluttered.
Edited to add: Also redirected a whole load of regular NTP queries to remain internal.
There's sweet FA traffic that should be going out to the 'net when everyone's asleep. But make sure these rules can be switched on and off in case of emergencies.
I had to take my daughter to emergency late one night a few months ago (didn't end up being anything worthy of a story), but got home at 2:30am. My garage door opener gets smart-home-switched-off at 1:00am-ish. At 2:30am, just wanting to go to bed after the stress of an emergnecy room, waiting for that thing to boot up felt like 15 minutes.
It seems so. This traffic likely will not even traverse a firewall -- the article lists the IP addresses used with port 52699, which are all RFC1918 space (172.16.0.0/12).
But also "Only allow HTTPS out to FAANG" - ok, so now you're allowing encrypted connections to 2 largest cloud providers. At that point what's the benefit at all?
This is a serious allegation to make. Do you happen to have some supporting evidence?
I do understand they don’t want to set any bad precedents internally, but their abuse reporting is abysmal.
It's kinda hard to point to someone saying how big the problem is, because most posts are just "sigh, here's yet another example, anyway...". I wouldn't go as far as saying they're doing this as an intended strategy, but it's definitely a case of it being hard for CloudFlare to care about an issue when they're in business of selling protection from that issue.
As a side note, I’m actually amused that I got downvoted for simply asking for evidence. I think it’s a pretty reasonable to ask folks to substantiate serious allegations made against a company like Cloudflare (a company, I might add, I’m not even a fan of for my own personal/philosophical reasons). I find this behavior very cult-like, but anyway, I digress…
CF are terribly slow to respond to abuse, their ranges are allowlisted everywhere, and it’s not terribly hard to hide your backend infrastructure (origin) even from cloudflare itself.
Sure you have to deal with the eventual takedown of your domain, by CF or more likely the domain registrar, but it’s trivial to work around that (backup domains, frequently rotating them, etc).
What’s funny is how Namecheap are now absolutely god tier at doing takedowns on malicious domains - they used to have a very poor reputation and now will process a takedown (provided evidence) within the hour usually.
A good solution is to block all outgoing traffic on production servers.