Protection → Protections, card Threats in the names
(administrators; free, beta, each check on by default; internal/threats).
The rule of the card: what leaves no doubt is blocked, the rest is told for
a person to decide.
- DNS rebinding (blocked): a name of Internet whose answer holds an
address of the home, the loopback (127.0.0.0/8, ::1), a link-local
address, or a private address (RFC 1918, ULA, 100.64.0.0/10) of a
network of the interfaces of the box (read again every 10 minutes): a web
page could drive the box, a camera or the NAS through the browser. The
public addresses, even those of the home (its IPv6 prefix, which a
dynamic DNS answers on purpose), the other private networks (a work
network, a VPN) and 0.0.0.0 (the answer of a filtering upstream) are
left alone, as
the local names and zones, the names an administrator allowed, and the
services that do it on purpose (
plex.direct,nip.io,sslip.io,ts.net,synology.me…threats.SafeRebinding). Reasonrebinding, originrebinding:<address>; It is expected allows a domain and its names (at most 200): a homelab that publishes the names of its services with their local addresses (for a certificate) needs it, as with the protection against the rebinding of OpenWrt or pfSense. - Spyware (blocked): the servers of the commercial spyware, from the
list
stalkerware.txtof warda-lists (the network indicators of Echap, CC BY 4.0; read from the repository of Echap until warda-lists publishes it; refreshed every 6 hours, taskstalkerware), for every device. Reasonspyware. The alert goes to the administrators (the device) and to the person of the device (noticespyware.mine,GET /api/v1/me/spyware, each withblocked, shown on their dashboard and their page My account, with what to do and a helpline of their language), whoever the administrators are: the one who installs such an app is often a close person. The person is told even when the blocking is off or an administrator allowed the domain for himself (then "not blocked"; the administrators get no alert of their own). - Remote access tools (told): AnyDesk, TeamViewer, RustDesk,
ScreenConnect, Splashtop, LogMeIn, Quick Assist, Chrome Remote Desktop…
(
threats.RemoteTools), used by the fake support scams: an alert the first time a device uses one (once a month by device and tool). To block them, block the service for a profile. - Beacons (told): a device that asks the same rare domain at a very regular interval (24 questions at least over 6 hours at least, the deviation of the intervals under 15 % of their mean, between one minute and two hours), a domain asked by that device only, neither a name protected against the look-alikes nor a known service (clouds, content networks), and young according to the online service (less than 180 days, so never with the second opinion off): a program driven from outside. Many connected objects talk to the servers of their maker that way, hence the age. At most 4096 device and domain pairs are followed; one alert a week by device and domain.
- Quarantine: Put in quarantine (on an alert of spyware or of a
beacon, or on Household → Devices) keeps a device away from
Internet: it gets only the local names and the names that heal it (the
updates of Windows, Apple, Android and Debian, the antivirus software, the
time and the certificates, Warda:
admin.Healing), until End the quarantine. It is a quarantine by the names: a program with its own resolver or addresses written in it goes around it; to cut a device off entirely, unplug it. Reasonquarantine; kept at a restart (quarantinein the settings); auditdevice.quarantine.on/off.
Each alert (rebinding, spyware, remote, beacon) is shown with the
others (see Alerts) and with the card. GET /api/v1/threats
gives rebinding, rebinding_allowed, networks, spyware,
spyware_domains, remote, beacons, found (the alerts of 30 days,
each with name and extra: the address of a rebinding, the interval of a
beacon) and quarantined (device ids); PUT /api/v1/threats takes
rebinding, rebinding_allowed, spyware, remote and beacons (audit
rebinding.on/off…, rebinding.allowed); PUT /api/v1/devices/{id}/quarantine {"on": true} (404 for a device not
known, 400 for this box).