# Accidentally DDOSing our network gateway with Node-Red

**URL:** <https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888>\
**Category:** General\
**Created:** [24 April 2023 16:16 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888 "2023-04-24T16:16:59Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darren](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/darren/32/92202_2.png) [@Darren](https://discourse.nodered.org/u/Darren)\
**Post date:** [24 April 2023 16:17 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/1 "2023-04-24T16:17:00Z")

</div>

Whether as a warning for the next guy, or a good laugh, here's a small adventure I had today:

I was running a localhosted version of node-red using Yarn, with some generic flows previously deployed to clients. I was also on our developer VPN, through which we can connect to clients' network gateways, small Linux boxes on which we run node-red, to talk to various PLCs on individual LANs. My localhost node-red was for [trying to connect to a modbus server on Gateway A](https://discourse.nodered.org/t/questions-about-modbus-ui-controls-and-forwarding-signals/77738).

My manager was trying to connect through Gateway B to reprogram a PLC, and while said PLC existed on that LAN and was pingable from the network gateway, all attempts at connection through GXWorks3 (PLC programming software) failed.

It wasn't until further investigation revealed that for some reason, my localhost node-red, which hadn't even successfully talked to Gateway A, was chatting nonsense to Gateway B and effectively DDOSing it.

😂

---

<div class="post-metadata">

**Author:** ![Darren](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/darren/32/92202_2.png) [@Darren](https://discourse.nodered.org/u/Darren)\
**Post date:** [24 April 2023 16:19 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/2 "2023-04-24T16:19:40Z")

</div>

Is there a specific setting we should enable to avoid this in future? Or are some flows just likely to spam the network? Strangely, these same flows have no issues when deployed onto all our network gateways, only when running off localhost on my work PC.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [24 April 2023 16:44 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/3 "2023-04-24T16:44:45Z")

</div>

What address was it trying to access? Did the node red log show anything?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [24 April 2023 21:55 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/4 "2023-04-24T21:55:58Z")

</div>

> [@Darren](#):
>
> Is there a specific setting we should enable to avoid this in future?

Maybe don't allow developers direct access to live services! 🤣 Surely a recipe for disaster.

---

<div class="post-metadata">

**Author:** ![Darren](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/darren/32/92202_2.png) [@Darren](https://discourse.nodered.org/u/Darren)\
**Post date:** [25 April 2023 08:19 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/5 "2023-04-25T08:19:51Z")

</div>

@TotallyInformation the idea was to test connection between 2x node-red servers, one of which was a newly-deployed production device (Gateway A) and the other, well, a harmless local server on my PC. We could have isolated them on a VPN, but didn't think node-red would flood the network.

@Colin only addresses it was explicitly trying to reach were

- `10.91.1.166:10502`,
- `192.168.127.254:502`,
- `192.168.127.4:502`,
- `192.168.127.6:502`,
- `10.91.1.190:5562`, (Modbus Read "testbench", IP of Gateway B)
- `192.168.127.10:502`  
but I believe most of those were unused. Gateway B's address was `10.91.1.190`, but we had no issues connecting to that, only to a PLC that was hidden behind that, and (I believe) on a different port, which node-red shouldn't be able to access.

I'll try and post the flows and log in the next posts.

---

<div class="post-metadata">

**Author:** ![Darren](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/darren/32/92202_2.png) [@Darren](https://discourse.nodered.org/u/Darren)\
**Post date:** [25 April 2023 08:27 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/6 "2023-04-25T08:27:09Z")

</div>

[Flows on Pastebin](https://pastebin.com/emPHedLs)

[Log on Pastebin](https://pastebin.com/kNx17WgR)

Too long for forum posts

---

<div class="post-metadata">

**Author:** ![Darren](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/darren/32/92202_2.png) [@Darren](https://discourse.nodered.org/u/Darren)\
**Post date:** [25 April 2023 08:33 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/7 "2023-04-25T08:33:17Z")

</div>

And... er... I think I found the answer.

That harmless little testbench modbus reader pile of nodes was actually trying to communicate on the same port that our programming software used. The issue arose because the network Gateway B was previously sitting on a testbench in the office where I connected to it, and we kept the same connection credentials on it after deployment.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [25 April 2023 09:21 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/8 "2023-04-25T09:21:03Z")

</div>

> [@Darren](#):
>
> The issue arose because the network gateway was previously sitting on a testbench in the office where I connected to it.

And, though it was firmly tongue-in-cheek, as an Enterprise Architect, I stand by my previous statement. If only due to the very real Murphy's Law, if it _could_ go wrong, it most certainly _will_. In our environments, doing experiments with live networks and services would not be allowed.

Not criticising, we've all been there and done it. And have the scars to prove it! 🤣

---

<div class="post-metadata">

**Author:** ![Darren](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/darren/32/92202_2.png) [@Darren](https://discourse.nodered.org/u/Darren)\
**Post date:** [25 April 2023 09:30 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/9 "2023-04-25T09:30:10Z")

</div>

Agree wholeheartedly; we need more testbenches around here, but not my call...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [9 May 2023 09:30 UTC](https://discourse.nodered.org/t/accidentally-ddosing-our-network-gateway-with-node-red/77888/10 "2023-05-09T09:30:45Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
