Re: AW: [EXTERNAL] Re: Guacamole Installation with separate servers for DMZ and Internal Setup

2020-05-30 Thread Nick Couchman
On Sat, May 30, 2020 at 3:13 AM Mike Jumper wrote: > On Thu, May 28, 2020, 14:18 Nick Couchman wrote: > >> On Thu, May 28, 2020 at 5:10 PM Peter De Tender wrote: >> >>> All, >>> >>> I agree on optimizing documentation could be a good project; maybe it >>> can be moved to a GitHub alike

Re: AW: [EXTERNAL] Re: Guacamole Installation with separate servers for DMZ and Internal Setup

2020-05-30 Thread Mike Jumper
On Thu, May 28, 2020, 14:18 Nick Couchman wrote: > On Thu, May 28, 2020 at 5:10 PM Peter De Tender wrote: > >> All, >> >> I agree on optimizing documentation could be a good project; maybe it can >> be moved to a GitHub alike scenario where "anyone" can contribute to it and >> improve it? >> >>

Re: AW: [EXTERNAL] Re: Guacamole Installation with separate servers for DMZ and Internal Setup

2020-05-28 Thread Nick Couchman
On Thu, May 28, 2020 at 5:10 PM Peter De Tender wrote: > All, > > I agree on optimizing documentation could be a good project; maybe it can > be moved to a GitHub alike scenario where "anyone" can contribute to it and > improve it? > > It already is :-)

Re: AW: [EXTERNAL] Re: Guacamole Installation with separate servers for DMZ and Internal Setup

2020-05-28 Thread Mike Jumper
On Thu, May 28, 2020, 10:29 Joachim Lindenberg wrote: > Can you please elaborate a little to what risk you are referring? Have you > been able to escape a guacd or guacamole or some other container? Via the > network interfaces exposed or how? Is there some thing to be done by the > project to

Re: AW: [EXTERNAL] Re: Guacamole Installation with separate servers for DMZ and Internal Setup

2020-05-28 Thread sciUser
Docker is popular however it comes with a serious security risk, its always better to build your own Guacamole instance over using Docker. The risk is in exploiting the host server through Docker container. I have actually done this and it can be pretty nasty if someone wanted to be malicious.