07-05-2021 04:08 AM
I am a security researcher from Baidu,Recently, we have detected a large number of hacking incidents from ddos attacks initiated on the UDP9001 port on the SmartZone-100 device. Great harm!!!
Refer to my screenshot for details.my phone number is 18903860673
My email address is 18903860673@163.com, I come from Baidu in China,Hope you guys get back to me as soon as possible,
07-05-2021 04:18 AM
Hello li_xiang,
We use port 9001 for Elastic Search DB update and also sync with member node in the vSZ/SZ Cluster. Please feel free to report a case with us for further investigation. Also make sure to mention the current firmware running on the SZ.
Regards,
Parikshith
07-05-2021 04:39 AM
@parikshith_nagaraj_aa0004 Can you tell me the business situation? What is the relationship between SmartZone-100 and ES, and why will ES services be deployed on SmartZone-100? At present, these SmartZone-100 devices still have problems. Port 9001 can accept any UDP request to respond to very large data packets, which will be used by hackers.
07-05-2021 05:06 AM
Hi @li_xiang,
As per the design, ES helps fetch data from Cassandra DB and present it to Web GUI. Also maintains the DB between different SZ Nodes in the cluster.
As suggested please feel free to report a case for further investigation.
Regards,
Parikshith
07-05-2021 05:15 AM
@parikshith_nagaraj_aa0004 Is the ES deployed on SZ an ES service or a plug-in