Opened 3 years ago

Last modified 2 years ago

#21 new defect

WNJ PO

Reported by: elven Owned by: somebody
Priority: major Milestone:
Component: component1 Version:
Keywords: Cc:

Description (last modified by elven)

VM 192.168.3.38
實體主機在 192.168.3.14

windows login:
wnjsoft / ji9wnjsoft@38

mssql
sa / ji9wnjsoft

VNC: ji9wnjsoft

Change History (4)

comment:1 Changed 3 years ago by elven

2022/05/25 因受攻擊,會不斷的的重新開機或關機,故重新安裝
作業系統改成 2019,資料庫改成 MS SQL Express 2019

comment:2 Changed 3 years ago by elven

Description: modified (diff)

comment:3 Changed 3 years ago by elven

Description: modified (diff)

comment:4 Changed 2 years ago by elven

PO server原本是開放port 3838直接NAT進來內部,但最近發現有被攻擊的記錄. 故關閉原本port 3838直接NAT到PO serer, 改成3838 NAT到nginx,然後透過nginx的設定,只有當 /PO/servlet的封包才會轉送到PO server,降低被攻擊的風險.

外部 po.wnjsoft.com:80 => nginx:80 => check /PO/servlet => PO server
外部 po.wnjsoft.com:3838 => nginx:3838 => check /PO/servlet => PO server

Version 0, edited 2 years ago by elven (next)
Note: See TracTickets for help on using tickets.