Serious and growing hack on easyengine sites - coming from local IP #1620
-
I just migrated about 6 sites to a brand new server with easyengine 4 setup. The migration went well but now it seems I have a disturbing and growing hack that I am trying unsuccessfully to track down. Here is what is happening:
|
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 1 reply
-
I guess I would assume the ee global_nginx_proxy would hold that IP, but it seems to be at 172.19.0.8. Maybe there is a bug in this proxy that allows certain requests to not have their correct IP forwarded to the other sites, and instead be passed 172.19.0.1? |
Beta Was this translation helpful? Give feedback.
-
Even if I disable ALL sites (leaving only the proxy and redis running apparently) I get spoofed IPs in the logs like this:
and sometimes error log entries like this:
How is this possible?? |
Beta Was this translation helpful? Give feedback.
-
I believe I found the problem and if I am correct it is a quite serious one for EE, pointing either to some problem with off the shelf, default ee setup or somehow something I have missed. But here it is in a nutshell:
|
Beta Was this translation helpful? Give feedback.
-
@ssuess Was this submitted and fixed? |
Beta Was this translation helpful? Give feedback.
I believe I found the problem and if I am correct it is a quite serious one for EE, pointing either to some problem with off the shelf, default ee setup or somehow something I have missed. But here it is in a nutshell:
I will report this in issues as a bug, but here is how I figured it out and tested it: