Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Im running virtual box in headless mode, and the way it works is it starts a RDP server on a specified port for you to RDP to. I want to access these virtual machines remotely, so I have forwarded the relevent ports in the modem/router. However this offers no authentication, and will let anyone get straight to the Login screen. Im a bit worried that Ive forgot to lock the screen a couple of times and others have been able to get into my VMs. Logs from the router/modem show connecitons on the RDP ports. Im not too sure how to tell if they were just scans of if they were able to get right through to the desktop (anything i can check in either the guest windows logs or the host linux logs?)

 

So what I want to do, is some sort of IP based restriction for these RDP ports.

 

Do i just add the ports and the allowed IP(s) to hosts.allow ? Is it as simple as that? Or do I need to implement IP tables? I dont want to lock down the whole box as I will need to ssh/squid/openvpn in from any random IP

 

Cheers

  • 2 weeks later...
Posted

robert@oasis ~ $ sudo iptables -A INPUT -p tcp -s IP_ADDRESS_TO_ALLOW --dport 3388:3392 -j ACCEPT
robert@oasis ~ $ sudo iptables -A INPUT -p tcp -s ANOTHER_IP_ADDRESS_TO_ALLOW --dport 3388:3392 -j ACCEPT
robert@oasis ~ $ sudo iptables -A INPUT -p tcp --dport 3388:3392 -j DROP

 

Thanks to powdarrmonkey for the above

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...