Skip to content
This repository has been archived by the owner on Dec 17, 2022. It is now read-only.

Terminating free ejemplo.me server #20

Closed
jerson opened this issue Dec 7, 2021 · 14 comments
Closed

Terminating free ejemplo.me server #20

jerson opened this issue Dec 7, 2021 · 14 comments

Comments

@jerson
Copy link
Owner

jerson commented Dec 7, 2021

sadly someone is using the service to expose malware, the only possible solution for me is to terminate ejemplo.me, you can still expose your own server using readme tutorial.

[PL-2738190] Phishing attack(s) hosted on: trending.ejemplo.me During an investigation of fraud, we discovered a compromised website (trending.ejemplo.me) that is being used to attack our client and their customers. In addition to the website owner, we have addressed this report to the responsible authoritative providers who have the ability to disable the malicious content in question. Based on your relationship to the content in question, please see our specific request below. This threat has been active for at least 0.4 hours. http://trending.ejemplo.me/login.html http://trending.ejemplo.me/ First detection of malicious activity: 12-06-2021 20:17:12 UTC Most recent observation of malicious activity: 12-06-2021 20:40:54 UTC Associated IP Addresses: 51.15.103.235 === HOSTING PROVIDER === If you agree that this is malicious, we kindly request that you take steps to have the content removed as soon as possible. It is highly likely that the intruder who set up this phishing content has also left additional fraudulent material on this server such as illegitimate access points. === WEBSITE OWNER === We recommend taking the following actions to secure the web site and prevent the attackers from returning: - Update your web applications including CMS, blog, ecommerce, and other applications (and all add-on modules/components/plugins). - Search all of your web directories for suspicious files as attackers commonly leave backdoors. - Scan the computer from which you login to your web hosting control panel or ftp server with anti-virus software. - Change your web hosting provider if this is an ongoing issue. If your provider has disabled your account because of this incident, you must coordinate a resolution with them directly as PhishLabs has no control over this aspect. If we have contacted you in error, or if there is a better way for us to report this incident, please let us know so that we may continue our investigation. We are grateful for your assistance. Kind regards, SOC Team PhishLabs Security Operations 12023866001 Available 24/7 [PL-2738190]

@jerson jerson pinned this issue Dec 7, 2021
@dwarfpuzzles
Copy link

Rest in peace.
Forever miss.

@MislavJancic
Copy link

Some people -_-

@lucdkny
Copy link

lucdkny commented Dec 9, 2021

Could you please share the detailed docs for self hosting pgrok?
I tried the one in "docs/SELFHOSTING.md" but it did not work.
Thank you.

@alisonreis1991
Copy link

usava bastante o pgrok aqui em casa, tem como você ativalo novamente?

@jerson
Copy link
Owner Author

jerson commented Dec 10, 2021

Hi @lucdkny yes this weekend im gonna update docs file to explains how to do it

@Alex-idk
Copy link

@jerson Quick question, can I run pgrok server without a domain if im just going to be using TCP tunnels?

@jerson
Copy link
Owner Author

jerson commented Dec 11, 2021

I just updated docs with more details about self hosting
https://github.com/jerson/pgrok/blob/master/docs/SELFHOSTING.md

and about @Alex-idk question, I havent tested using only tcp so, im not sure about that but probably you can use https://github.com/fatedier/frp which has a better implementation for expose ports

@dwarfpuzzles
Copy link

Does ejemplo.me support TCP still?

@jerson
Copy link
Owner Author

jerson commented Dec 11, 2021

@dwarfpuzzles no, for now the service is down since i can not avoid that someone can expose malware using ports too,

@dwarfpuzzles
Copy link

ngrok has this problem as well

@jerson
Copy link
Owner Author

jerson commented Dec 11, 2021

Actually you can protect you pgrok instance using client certificates and CA, doc was included in Protect you client(pgrok) to server(pgrokd) connection with a CA

Section

@SumirekoUsami
Copy link

Huh, a bruh moment indeed. It's sad to see this service being shut down, it truly was a very convenient way to share localhosted websites to the internet without configuration :(
I think that now, without a public pgrokd instance, people who don't have their own server with static IPs will not be able to use pgrok as before? If that's the case, would you consider changing the default server to another one, hosted by someone, who has the will (and time and resources) to take care of malware issues (and others)? :D
I personally think that using pgrok without selfhosting is a very popular usage case and that's why I believe this issue is important. My hosting provider also happens to forward all copyright/fishing claims to it's clients before taking any action too, so... I suppose I can host a public pgrok instance, yay.

@Alex-idk
Copy link

I mean pgrok isn't the only thing to forward localhost things with there is ngrok, localhost.run, pagekite.net, or a plain old ssh port forwarding to a vps

@alisonreis1991
Copy link

Jerson, how can i make pgrok work on my pc, could you make a video showing how i can make it work on my computer?

Repository owner locked and limited conversation to collaborators Feb 8, 2022
@jerson jerson closed this as completed Feb 8, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants