Jump to content

Recommended Posts

crusher11
Posted (edited)

No idea how they're getting to it, as it's a Hong Kong IP address and CloudFlare is blocking traffic from outside Australia. Three failed login attempts in the past ten minutes, one trying to log in as “root.” I see the alerts on my dashboard, but what I don't see is any way to block the offending IP? Not sure what autoban conditions exist, but since I'm on my server machine right now it seems silly to wait for it to kick in when I could just push a button. Is there no way to do that? And if it does get autobanned, I assume that's only for a period of time.

Not sure what other steps I should be taking here.

EDIT: I've disabled all remote connections for now, but it's obviously not the best solution.

EDIT 2: It's not a solution at all, it seems, as even with remote connections disabled I've just had another two failed login attempts, this time from Kansas City (the US is also on my CloudFlare whitelist, so that at least makes more sense than the Hong Kong efforts, though how it's connecting with all remote connections disallowed I don't know).

Edited by crusher11
Lessaj
Posted

Sounds like you need to review your Cloudflare config or talk to them. Otherwise:

image.png.9596684ea16a88dc07da249a0f0ec6f1.png

crusher11
Posted
Just now, Lessaj said:

Sounds like you need to review your Cloudflare config or talk to them. Otherwise:

image.png.9596684ea16a88dc07da249a0f0ec6f1.png

Not sure if you saw my second edit, as you posted only a few seconds after I made it.

Which settings page is this screenshot from?

Lessaj
Posted

I did not. That's on the Network page.

crusher11
Posted

Ah, right, I couldn't see it because it disappears if you disable all remote connections.

There really ought to be a way to add an address directly to that list from the “failed login attempt” alert.

Still no idea how they bypassed the CloudFlare block, or how they connected when all remote connections were disabled in Emby, or why I've suddenly had a bunch of attacks come in.

Lessaj
Posted

Based on my understanding the option for allow remote connections doesn't prevent the connection entirely, it just prevents logins. If the port is open, then it's open. You'd have to close the port/Cloudflare tunnel to fully disable remote connections. I can't test on my system at the moment to confirm that.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...