# Advice on any security concerns accepting HTTP posts from public facing port?

**URL:** <https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040>\
**Category:** General\
**Tags:** security\
**Created:** [26 December 2023 14:52 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040 "2023-12-26T14:52:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fatpanda](https://avatars.discourse-cdn.com/v4/letter/f/b5ac83/32.png) [@fatpanda](https://discourse.nodered.org/u/fatpanda)\
**Post date:** [26 December 2023 14:52 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040/1 "2023-12-26T14:52:33Z")

</div>

Hi All,

For those using NR in the enterprise, I need to have a flow that is essentially a custom http webhook receiver (the incoming information is not confidential in any way) collecting information from devices that are online but cannot connect via vpn.

Although I've been using NR for a while now, I've not put anything out on a public facing connection before and just want to make sure those of you with more experience dont see an issue.

My NR install is running as a regular (non-root) user  
my webhook receiver is not on port 80 and is different port from my dashboard port  
the webhook incoming port is the only hole in the firewall.  
the NR instance is in an isolated DMZ that can only forward verified messages to an SQL server  
the nr dashboard is "secure" and can only be accessed from my admin machine

I have safeguards in place for getting junk/malicious incoming posts and I've attempted to handle DoS attacks.

Are there any concerns you see in this kind of setup?

Thanks for any insights!

---

<div class="post-metadata">

**Author:** ![jodelkoenig](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jodelkoenig/32/44645_2.png) [@jodelkoenig](https://discourse.nodered.org/u/jodelkoenig)\
**Post date:** [26 December 2023 15:21 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040/2 "2023-12-26T15:21:14Z")

</div>

There have been recent reports about hacked node red instances, right after ports have been opened on routers. Hence I'd be really really careful. There are bots waiting for you. And I guess its independent from the ports you use.

> [@Nodered hacked by adding invisible nodes](https://discourse.nodered.org/t/nodered-hacked-by-adding-invisible-nodes/83860):
>
> Hello Everyone My nodered server has been hacked, by adding some invisible nodes to my flows.json while I was working on it. I detected it because of a nodered message stating that some nodes where changed without ay action from me. Looked like someone edited another instance of the flows.json file. Consequence was that server (a RPi) was damaged and had to reformat and resintall everything. Well, of course I might have made some mistakes in securing my server to allow that, but as my knowle…

> [@All flows have disappeared on AWS hosted system](https://discourse.nodered.org/t/all-flows-have-disappeared-on-aws-hosted-system/83569/2):
>
> How do you expose your AWS Ubuntu instance to the internet? It might be related: As for recovery. Does AWS do backups or snapshots for instances?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [26 December 2023 15:46 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040/3 "2023-12-26T15:46:00Z")

</div>

> [@fatpanda](#):
>
> that can only forward verified messages to an SQL server

Do you use parameters and/or stored procedures OR constructed SQL insert strings? This is important to avoid SQL injection hacks

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [27 December 2023 13:12 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040/4 "2023-12-27T13:12:04Z")

</div>

This looks good on casual read.

As long as you are validating the webhook inputs correctly and not allowing any other access to the server, should be good.

From your post, I assume you don't need any lessons on validating remote inputs 🙂

For others, you need to do things like limit input parameter sizes, validate everything, ...

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [27 December 2023 13:13 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040/5 "2023-12-27T13:13:05Z")

</div>

> [@jodelkoenig](#):
>
> recent reports about hacked node red instances

Thankfully, that doesn't apply here as only the webhook URL is open, nothing else.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [25 February 2024 13:13 UTC](https://discourse.nodered.org/t/advice-on-any-security-concerns-accepting-http-posts-from-public-facing-port/84040/6 "2024-02-25T13:13:58Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
