How to disable HTTP commands?

Moderators: grovkillen, Stuntteam, TD-er

Post Reply
Message
Author
backonline
New user
Posts: 2
Joined: 09 Dec 2016, 19:47

How to disable HTTP commands?

#1 Post by backonline » 11 Dec 2016, 14:51

So, since i'm using mqtt with autentication i need to block any http commands, is it possible?
Because this is an huge security risk.

Many thanks.

mikeluyten
New user
Posts: 5
Joined: 24 Oct 2016, 05:57

Re: How to disable HTTP commands?

#2 Post by mikeluyten » 16 Dec 2016, 07:54

What part is a security risk? the HTTP commands should be quite limited, the best you should be able to get from http is the status of a specific gpio.

JR01
Normal user
Posts: 260
Joined: 14 Feb 2016, 21:04
Location: South Africa

Re: How to disable HTTP commands?

#3 Post by JR01 » 31 Dec 2016, 10:04

... and actuate a gpio pin to say a relay, on http, without password, .... So I also think it would be better if we are able to disable for instance actuation of gpio pins, and limit a hacker reading the json back about what Tasks are setup on the device.
-----------
IOTPLAY. Tinkerer, my projects are @ http://GitHub.com/IoTPlay, and blog https://iotplay.org. Using RPi, Node-Red, ESP8266 to prove Industry 4.0 concepts.

backonline
New user
Posts: 2
Joined: 09 Dec 2016, 19:47

Re: How to disable HTTP commands?

#4 Post by backonline » 12 Feb 2017, 02:21

I have 2 arubas access Point, they have the possibility to create Access Rules, so what i've done is create a new SSID and permit only comunications from the pears to my Firewall to the NTP port and to my MQTT server and is port, every thing else is droped.
So, no one can access my pears from this SSID nor my internal network because it's beind an SOPHOS Firewall.

Post Reply

Who is online

Users browsing this forum: Ahrefs [Bot] and 21 guests