• @dariusj18@lemmy.world
    link
    fedilink
    English
    4124 days ago

    Got worried about a synching vuln, but no, they are just using it as a file transfer agent for their own malware.

        • KidOPM
          link
          fedilink
          English
          624 days ago

          Honestly, I didn’t think about vulnerability in SyncThing when I read the article. But I wondered why defense forces would have p2p open on their networks.

          • slazer2au
            link
            fedilink
            English
            424 days ago

            When you say P2P you think torrents. But syncthing have rendezvou helpers to facilitate connections without seeing any data.

            • KidOPM
              link
              fedilink
              English
              624 days ago

              Not necessarily. Torrent is a way to find a peer for direct connection or via a relay (of course that is more than that). Syncthing, even using a relay server, requires some ports available for at least outbound connection (22000 TCP/UDP or whatever port the relay is using). This should not be possible in a medium security network, let alone a defense network. I don’t know if syncthing works without a direct connection (to the peer or relay, something like transport via http proxy).

              • @jetA
                link
                English
                524 days ago

                It does. It has hole punching incorporated into the protocol. So as long as it can get to the internet, it can use coordination servers and do double hole punching so that they can talk to each other

                • KidOPM
                  link
                  fedilink
                  English
                  224 days ago

                  Interesting. I didn’t know that syncthing does hole punching.

                  From a defense perspective, how would this work with an enterprise firewall, with UDP/TCP only allowed to specific destinations or specific sources. Example: only the internal DNS relay server can access 53/UDP and only the internal proxy server can access 80/443. What I mean is in a network with a very closed firewall, how would Syncthing be able to connect with peers?

  • @jetA
    link
    English
    18
    edit-2
    24 days ago

    Use… Not abuse.

    I just lost a bunch of respect for bleeping computer