Is the security of a web server a concern?

Talk about anything you want!
Post Reply
w5uxh
Posts: 40
Joined: Mon Jun 02, 2014 6:29 pm
Location: Las Cruces, NM USA
Contact:

Is the security of a web server a concern?

Post by w5uxh » Mon Aug 24, 2015 6:31 pm

I am starting to work with the WF32 web server example from Digilent. I have forwarded port 80 to the WF32 on my local network.

Are there any concerns I need to be aware of where the outside world could connect to the WF32 through the web server and find a way to the Mac and / or Windows machines on my network?

rasmadrak
Posts: 218
Joined: Mon Aug 15, 2011 9:21 pm
Location: Sweden
Contact:

Re: Is the security of a web server a concern?

Post by rasmadrak » Thu Sep 24, 2015 10:15 pm

Yes, same as with any network. But it depends on what you intend to do with it.
Let's say your using the webserver to access door locks from the outside...that would be a very bad idea to do without proper safety.

In your case -
Say that all machines are connected through a local network that is reachable from the outside.
All machines are therefor possibly at risk from the outside since the devices doesn't have to understand or process malicious code (if done "right") to spread it to other machines. This mean any device capable of sending and receiving IP-packets is at risk - and is a risk in itself.

TL;DR -
If the network is reachable from the outside - it must be protected.

w5uxh
Posts: 40
Joined: Mon Jun 02, 2014 6:29 pm
Location: Las Cruces, NM USA
Contact:

Re: Is the security of a web server a concern?

Post by w5uxh » Thu Sep 24, 2015 10:31 pm

Thanks for the comments. When I played with the port 80 requests for a bit, I noticed lots of "probes", some looking for "ram-0" or "rom-0" or something similar and learned from google that is a probe for a potential weakness in routers, but it was enough to scare me off.

After deciding I would not be comfortable enough running the web server for control of my device, I took an alternate route. The specific function is to allow others to control a program running in the PIC32. The program is reading text from the SD card and sending "Morse Code" to a desktop sound card which streams it to a Mumble server. I want "listeners" who are using it for practice to be able to control the speed, and the selection of text etc.

It would be fun to learn how to do that with a web server, but instead, I am letting them do it by sending very simple commands back over the full duplex audio stream.

Post Reply