Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Is ngrok safe to use or can it be compromised?

Tags:

security

ngrok

Is ngrok a safe tool to use? I was reading a tutorial which recommended to use ngrok test API responses that I make to outside services that need to connect to my endpoints also.

like image 263
cool breeze Avatar asked Apr 11 '16 15:04

cool breeze


People also ask

Can Ngrok be trusted?

ngrok Secure Tunnels allow you to instantly open access to remote systems without touching any of your network settings or opening any ports on your router. This means you get a secure, reliable tunnel for your developer box, IoT device, or just about anything that has access to the internet.

Can Ngrok be hacked?

In addition, ngrok is used by hackers to deliver phishing attacks. Ngrok can bypass a firewall, and it uses a random temporary subdomain which makes it hard to detect. Hackers see this as an opportunity to create a server that can deliver a malicious code to any one who clicks the URL in a phishing email.

Is Ngrok malicious?

Ngrok is a legitimate remote-access tool. It is regularly abused by attackers, who use its capabilities and reputation to maneuver while bypassing network protections.

Does Ngrok collect data?

ngrok may collect, retain, use, and disclose data and other information about you and your users, including but not limited to Customer Data, subject to the terms of ngrok's Privacy Policy.


1 Answers

There is no source code available for Version 2.0, considering it started as an open source project in 2014. I am suspect of any code that opens a tunnel to my localhost from the cloud. Pretty scary stuff especially without source code!

like image 180
topquant Avatar answered Sep 18 '22 19:09

topquant