Quote:
Originally Posted by Ripplinger
Yeah, it's definitely not something you want to leave open 24/7 even with a password. If you have a friend who wants to browse your books and maybe grab a few, then do it for that short time when they'll be connecting, and then undo the port forwarding when they're done. It's nice to work through it so you know how to do it and have that option if and when needed.
|
Can you identify specifics of the threat scenario you contemplate? The attacker has to find your address, find your port, then identify a weakness in the server (which may necessitate finding the password). I know the first two are obscurity only protections, but they do limit the threats. Do we know of any weaknesses in cherrypy or Calibre? My logs don't show any attacks that have ever even scanned my Calibre port.