Alicloud security group rule exposes sensitive ports

Avoid unnecessary internet-wide access to administrative or sensitive services.

Description

Allowing an administrative or sensitive service port from 0.0.0.0/0 permits external connection attempts when the server has an internet path. Vulnerable services or weak authentication can increase the risk of compromise.

A port number alone does not establish whether a service is safe. Identify the actual listening service and why it needs public access. Restrict internal or administrative services to approved networks or administrator addresses.

Potential impact

  • External clients may attempt password guessing or exploit service vulnerabilities.
  • Sensitive data or administrative functions may face increased access risk.

Remediation

  • Remove internet-wide grants for services that do not require public access.
  • Allow only required ports and approved sources, while maintaining service authentication and security updates.
  • Where a public service is necessary, document its purpose and review the actual connection path and other allow rules.

Examples

These excerpts use an existing security group. VPC security groups require nic_type = "intranet"; this does not automatically block internet traffic.

Before

hcl
resource "alicloud_security_group_rule" "sensitive_port_open" {
  type              = "ingress"
  ip_protocol       = "tcp"
  nic_type          = "internet"
  policy            = "accept"
  port_range        = "19/20"
  priority          = 1
  security_group_id = alicloud_security_group.default.id
  cidr_ip           = "0.0.0.0/0"
}

TCP 19–20 is allowed from all IPv4 addresses. Verify the actual service and whether this public scope is required.

After

hcl
resource "alicloud_security_group_rule" "sensitive_port_open" {
  type              = "ingress"
  ip_protocol       = "tcp"
  nic_type          = "internet"
  policy            = "accept"
  port_range        = "22/22"
  priority          = 1
  security_group_id = alicloud_security_group.default.id
  cidr_ip           = "10.159.6.18/32"
}

Assuming only SSH administration is needed, the rule is changed to TCP 22 from one approved client. Use the address appropriate to the actual connection path and remove the earlier public rule.

References