# Don’t leave your Syncthing open to the world…

**URL:** https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777
**Category:** General
**Created:** [February 9, 2023, 8:55pm UTC](https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777 "2023-02-09T20:55:27Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![calmh](https://forum.syncthing.net/user_avatar/forum.syncthing.net/calmh/32/15311_2.png) [@calmh](https://forum.syncthing.net/u/calmh)
#### Post date: [February 9, 2023, 8:55pm UTC](https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777/1 "2023-02-09T20:55:27Z")

</div>

> **[kms.nhp.gov.in rooted via syncthing - Tethik's weblog](https://joakim.uddholm.com/posts/kms-nhp-gov-in-rooted-via-syncthing/)**
>
> In May last year (2022) I found and disclosed a vulnerability on a subdomain of nhp.gov.in. Using an exposed syncthing admin interface, I was able to gain root SSH access to the server by syncing the \`/root/.ssh\` directory.

And maybe also not running as root… The excerpt summarises it quite well.

---

<div class="post-metadata">

### Author: ![bt90](https://forum.syncthing.net/user_avatar/forum.syncthing.net/bt90/32/18565_2.png) [@bt90](https://forum.syncthing.net/u/bt90)
#### Post date: [February 9, 2023, 9:25pm UTC](https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777/2 "2023-02-09T21:25:50Z")

</div>

I strongly support a disbarment of IT folks who operate such setups.

---

<div class="post-metadata">

### Author: ![anaqreon](https://forum.syncthing.net/user_avatar/forum.syncthing.net/anaqreon/32/5218_2.png) [@anaqreon](https://forum.syncthing.net/u/anaqreon)
#### Post date: [February 10, 2023, 9:58pm UTC](https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777/3 "2023-02-10T21:58:38Z")

</div>

Wow. I guess that’s good advice. While we are at it, let’s warn people not to post their banking credentials to Twitter 🙄

In my opinion, using the phrase “rooted via syncthing” is almost defamation in this context.

---

<div class="post-metadata">

### Author: ![slokdfgvhnisudfhbois](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/s/77aa72/32.png) [@slokdfgvhnisudfhbois](https://forum.syncthing.net/u/slokdfgvhnisudfhbois)
#### Post date: [February 16, 2023, 5:23pm UTC](https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777/4 "2023-02-16T17:23:47Z")

</div>

Is it not the first thing Syncthing tells you to do, to set an admin password for the GUI? :facepalm:

---

<div class="post-metadata">

### Author: ![tomasz86](https://forum.syncthing.net/letter_avatar_proxy/v4/letter/t/96bed5/32.png) [@tomasz86](https://forum.syncthing.net/u/tomasz86)
#### Post date: [February 17, 2023, 11:07am UTC](https://forum.syncthing.net/t/don-t-leave-your-syncthing-open-to-the-world/19777/5 "2023-02-17T11:07:13Z")

</div>

That’s probably still not enough, as some people will use a password called “password” or “12345678” 😉. I think there was a feature request some time ago asking for calculating and showing the password strength, although I believe it was related to the “Receive Encrypted” password and not the GUI.
