Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Fri Aug 19, 2011 1:37 am 
Offline
Senior Member

Joined: Tue Jun 21, 2011 4:25 pm
Posts: 118
Website: http://www.alohatone.com
Location: Hawaii
So we have our linode manager locked down to only 4 ips that can access the manager.

Using the Android app, I can access the manager from an ip not on our list.

- got an updated list of linodes (bought more today that I know wouldn't have been cahced)

- was able to issue a reboot command on a node.


Last edited by Alohatone on Fri Aug 19, 2011 1:44 am, edited 1 time in total.

Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 1:43 am 
Offline
Senior Member

Joined: Tue Jun 21, 2011 4:25 pm
Posts: 118
Website: http://www.alohatone.com
Location: Hawaii
might have been a fluke - but I was able to order a reboot...

Host Job Queue (more)
Success
System Boot - My PV-GRUB el5-xen
Entered: 9 minutes 22 seconds ago - Took: 6 seconds
Success
System Shutdown
Entered: 9 minutes 22 seconds ago - Took: 29 seconds

Then couple minutes later, the app was denied due to authentication.


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 3:34 am 
Offline
Senior Member

Joined: Tue Jun 21, 2011 4:25 pm
Posts: 118
Website: http://www.alohatone.com
Location: Hawaii
tried it from 3G , so for sure the IP was never authorized.

I was able to shut down a node.


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 3:41 am 
Offline
Senior Member

Joined: Fri May 02, 2008 8:44 pm
Posts: 1121
This behavior might be intentional.

Mobile devices tend to change IP addresses quite often. If you had to whitelist your dynamically assigned IP every time your phone picked up another station's signal, the mobile app would be very annoying to use.


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 3:44 am 
Offline
Senior Member

Joined: Tue Jun 21, 2011 4:25 pm
Posts: 118
Website: http://www.alohatone.com
Location: Hawaii
hybinet wrote:
This behavior might be intentional.

Mobile devices tend to change IP addresses quite often. If you had to whitelist your dynamically assigned IP every time your phone picked up another station's signal, the mobile app would be very annoying to use.


I don't think its intentional, it eventually gets blocked , but only after someone who found your phone deleted your node.

Its probably running through a proxy that is whitelisted by linode. Only ask for authentication after a transaction.

I also doubt its intentional - why have a deny list on the manager if the mobile app just bypasses it? security wise, having a mobile device accessing the manager makes it even harder to stop than someone from a fixed IP....


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 8:08 am 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
Pretty sure the Android app (which was written by someone not-Linode) uses the API, and the IP-based whitelisting only applies to the dashboard web interface.

_________________
Code:
/* TODO: need to add signature to posts */


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 9:47 am 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
hoopycat wrote:
Pretty sure the Android app (which was written by someone not-Linode) uses the API, and the IP-based whitelisting only applies to the dashboard web interface.


It's definitely written by someone not-linode (who posts here), it definitely uses the API. I'm pretty sure you're correct that the IP whitelist applies only to the dashboard.


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 1:26 pm 
Offline
Senior Member
User avatar

Joined: Fri Oct 24, 2003 3:51 pm
Posts: 965
Location: Netherlands
glg wrote:
I'm pretty sure you're correct that the IP whitelist applies only to the dashboard.

Yes -- only the dashboard.

_________________
/ Peter


Top
   
 Post subject:
PostPosted: Fri Aug 19, 2011 1:39 pm 
Offline
Senior Member

Joined: Tue Jun 21, 2011 4:25 pm
Posts: 118
Website: http://www.alohatone.com
Location: Hawaii
the app does get blocked after a couple minutes (just FYI)...


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group