Skip to content

Serious and growing hack on easyengine sites - coming from local IP #1620

Answered by ssuess
ssuess asked this question in Support Requests
Discussion options

You must be logged in to vote

I believe I found the problem and if I am correct it is a quite serious one for EE, pointing either to some problem with off the shelf, default ee setup or somehow something I have missed. But here it is in a nutshell:

  • On EE machines that have IPv6 enabled, an IPv6 request will get translated by the proxy to internal local IPv4
  • This allows all number of attempted hacks to bypass security mechanisms, BECAUSE THEY APPEAR TO BE LOCAL
    I will report this in issues as a bug, but here is how I figured it out and tested it:
  • ran an ipv6 reachability test (https://ipv6-test.com/validate.php) on a couple of my sites (one ee, one manual setup on another machine) which both passed.
  • When i check the l…

Replies: 4 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by ssuess
Comment options

You must be logged in to vote
1 reply
@ssuess
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants