-
Notifications
You must be signed in to change notification settings - Fork 113
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SECURITY] NanoKVM is a router #197
Comments
Good, thanks for informing. |
This should be configurable. I like having nanokvm setup as a tailscale router |
The In the next version, Tailscale will not start automatically at boot. IP forwarding will only be enabled when Tailscale is started manually and disabled when stopped. |
In the meantime, empty the file and make it immutable |
This stopped me from buying this china spy shit - https://youtu.be/plJGZQ35Q6I?t=1386 |
You can Flash the Image v.1.4.0 , Tailscale is disabled by default. The router is also disabled by default, and the Alternatively, update the Application to 2.2.0 , and disable Tailscale in the web settings. This deletes the |
NanoKVM v1.3.0 image (20241120_NanoKVM_Rev1_3_0.img.xz) comes with IPv4 and IPv6 routing enabled, with firewall accepting all routed connections unconditionally.
When IP forwarding is enabled, the device can potentially forward packets between different networks, which might expose internal network to unauthorized access or attacks.
https://www.tenable.com/plugins/nessus/50686
NanoKVM is not a router, hence this function should be disabled.
Forwarding is enabled by
/etc/sysctl.d/99-tailscale.conf
, which I assume is not necessary for the client configuration.Workaround:
The text was updated successfully, but these errors were encountered: