ccnet-WI: disable QNAP telnet listener (port 13131) once SSH is confirmed stable #29
Labels
No labels
blocked
borg-backup
ceph
forgejo
in-progress
infra
netdata
nextcloud
p:high
p:low
p:medium
searxng
service-onboard
swarm-nodes
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
copper/ccnet-prod-devops#29
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Telnet on port 13131 was enabled 2026-07-13 to diagnose/fix the QNAP's broken SSH host keys (see docs/ccnet-wi-site.md). SSH is fixed and working. This unencrypted, unauthenticated-by-default admin channel should be disabled once SSH is confirmed stable across a few days of normal use -- it's a real exposure on hardware that can no longer be patched. Disable via the QTS web UI (Control Panel > Network & File Services > Telnet/SSH) or the equivalent config toggle, then confirm nothing is listening on 13131.