1/8/2024 0 Comments Url redirector hack![]() ![]() The first approach is to take advantage of default credentials. In general, there are two basic ways to hijack a router. Let’s take a closer look at phishing schemes that involve hijacked routers. In fact, you can follow a whole bunch of standard rules - avoid using public Wi-Fi, hover over links before clicking, and so forth - but in the situation we discuss here, those rules won’t help. But today’s router-based phishing doesn’t require you to fall for a hoax e-mail message. location / context.What is the most common threat across cyberspace these days? It’s still phishing - there’s nothing new under the sun. At this point however I have the server running, with Nginx, and am ready to test out a redirect.Ī lot of the samples I find all over the web are in little snippets like the following. So I’ll have to figure that out later as I work through automating and building out this server for deployment and prep with Packer and Terraform later. I noticed this prompted for a “ y|n“ as I enabled the firewall. Some instructions point to an Nginx HTTP so I added that too. To setup that firewall, open up the HTTP and SSH ports. On Ubuntu 16.04 a new firewall technology is used called Uncomplicated Firewall ( UFW). gcloud compute -project "that-big-universe" ssh -zone "us-central1-a" "url-redirector"Īt this point I went ahead and logged into this new instance and installed Nginx. I copied the command to ssh into my Google Cloud server instance. A dialog appears with the gcloud command to connect to this new instance. There I have my IP and SSH options.Ĭlicking on the SSH vertical elipsis I then selected the View gcloud command option. Once created it displayed on the Compute Engine dashboard screen. For that instance I named it url-redirector, stuck it in the us-central1-a zone, selected the micro (1 shared vCPU) with 0.6 GB Memory, using the Ubuntu 16.04 LTS image, gave it default access, selected HTTP traffic, and clicked create. In my particular situation I’m assuming an almost non-existent need for resources so I’ve select the uber cheapo $4.49 instance. Next setup the criteria for the instance. Here’s the interface for creating a new instance on Google Compute Engine ( GCE). Setting up Nginxīefore getting into a smart way to setup Nginx, I just dove in to figure out how to setup a redirect.įirst I spun up an Ubuntu 16.04 Server on Google Cloud. I determined I’d go with Nginx as I knew it to be a solid server with minimal fuss. ![]() Have a subdomain, like redirect (302 and eventually 301, more on that in a minute) to something like. When I stumbled into the fact that there were some URL Redirects that had muddled themselves into Google DNS as actual CNAME DNS entries, I knew I’d need to get those migrated to something that could actually do URL redirects. ![]() Google DNS doesn’t convolute their DNS Services with URL Redirect features or other non-DNS features. This whole setup started when I realized while doing a migration from one DNS Provider to Google DNS. Is this a best practice way to do subdomain to URL Redirects? If not, I’d probably like to be doing whatever is best practice.Īnyway, now that we’re past my caveats, questions, and requests for help, let’s roll on the how-to of all this.If you have any suggestions for an easier way than spinning up a whole Nginx Server to do URL Redirects I’d love to hear them!.With those two caveats I’ll add a few questions for you, dear reader. ![]() They work, but it seems like there really ought to be a better less onion layer like way to do this type of redirection. URL Redirects of this sort actually seem like a hack. I’ve no idea really if this is even a good practice.But other than that, I’ve barely done anything myself with Nginx. Theoretically it worked (in their testing). I’ve written up and configured one reverse proxy and handed that off to some ops team. I don’t really know much about Nginx at all.Before I even get into the nitty gritty of how I got this to work via Nginx, I’ll add two caveats: I set out on a mission yesterday to put together a URL Redirect Server. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |