Skip to content

Coturn is being abused for an amplification attack #3900

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
R0CKB0TT0M opened this issue May 30, 2025 · 0 comments
Open

Coturn is being abused for an amplification attack #3900

R0CKB0TT0M opened this issue May 30, 2025 · 0 comments

Comments

@R0CKB0TT0M
Copy link

Just putting this here so people see it and can take action. This is not a netbird issue.
A colleague at work just told me about this and looking at the coturn logs of my self hosted server I did see some suspicious IP addresses in the logs. This is an issue for the coturn people to figure out but it's probably a good idea to disable coturn in your setup before your ISP or vps provider bans you. As far as I know netbird only uses coturn for fallback so disabling it should be fine for most Users.
See the link below for more information.

https://www.reddit.com/r/selfhosted/s/5hAsU6WXN6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants
@R0CKB0TT0M and others