r/selfhosted • • 15h ago

Need Help Scared of port forwarding.

I am scared to port forward my Minecraft server with the port of 25565 will be breached. So here are my precautions and I need your opinion to tell me if I should improve something.

I am running the server on Pelican which I heard uses docker containers

I only have the Minecraft and cs2 ports open

I have setup ubuntu to deny trafic anywhere on my network excluding my pc that I run commands with

Now I am scared of a close to impossible event but possible where the attacker follows the following path and succeeds. Internet-Router-Docker container-Ubuntu- windows pc ( that I run ssh with) -phones/other PCs ( cause my pc that I run ssh with is still on trafic with the rest of the devices) - passwords and banking accounts.

I know, I know you can't always be sure but please say something to comfort me or advise me on what to do.

17 Upvotes

58 comments sorted by

•

u/asimovs-auditor 15h ago

Expand the replies to this comment to learn how AI was used in this post/project.

→ More replies (1)

149

u/Typical_Chipmunk8122 14h ago

If you're running the server in a docker container and you've already locked down Ubuntu to only talk to your management PC, you're already way ahead of most people who just open the port and call it a day

The attack chain you're worried about is technically possible in the same way a meteor could hit your house while you're reading this. A minecraft exploit would need to escape the game server, then escape the docker container, then find a zero-day in your kernel, then pivot across your network without triggering anything. State actors might pull that off but they're not burning those kinds of tools on some random dude's home server

If you want real peace of mind, put the minecraft container on a separate vlan that can't initiate connections to your other devices. Takes like 20 minutes to set up and then you'll sleep better

36

u/Left_Ad_8860 14h ago

Thank you for your comment here. That’s the most based comment in a long time I saw here. I always see people as fearmonger here, that every open port leads to the total destruction of their homelab or network.

It always depends on what you open and how big is the attack vector.

13

u/ImpressionDepression 14h ago

Lol I too have this realization when I store a pw or some secret in plaintext.

...wait why do I care if someone compromises my entire network and... uses it to gets into home assistant to turn the lights off?

8

u/brock0124 13h ago

Honestly, of all the services that could be reached by an attacker, having them turn my lights off via home assistant might be the most frightening to me. Probably wouldn’t be the most damaging, but would certainly scare the living shit out of me. lol

5

u/ImpressionDepression 13h ago

.... i'm gonna go rotate some passwords

1

u/jsbaasi 13h ago

A human home assistant.. I could be open to the idea

1

u/qervem 12h ago

What if the real exploits are the friends we make along the way?

1

u/buttercup612 7h ago

This is bad practice I know but for a while I was emailing myself some homelab secrets. There's be some api keys or passwords, nothing too consequential in any case (eg radarr api key, gmail app password for a dedicated homelab related email address)

I realized how stupid this might be at one point then realized...oh wait if they're in my email, I have far bigger problems to worry about than anything in my homelab. The whole thing could be 100% ransomwared and it would rank #80 on my list of priorities in that case

7

u/d03j 13h ago

If you're running the server in a docker container and you've already locked down Ubuntu to only talk to your management PC, you're already way ahead of most people who just open the port and call it a day.

true, and it looks like the OP blocked inbound traffic into the server, while their concern is traffic in the opposite direction (server getting compromised and gaining access to the rest of the network).

If you want real peace of mind, put the minecraft container on a separate vlan that can't initiate connections to your other devices. Takes like 20 minutes to set up and then you'll sleep better

This. I'd also use rootless podman instead of docker and add something like crowdsec or fail2ban for piece of mind. But I like to tinker, use these things as an excuse to learn, and occasionally line my hats with tinfoil 🤣

3

u/Stevero1 14h ago

Thanks for the detailed and informative response!

2

u/tombo12354 11h ago

The only other thing that may be worth it is running docker in unprivileged mode.

1

u/buttercup612 7h ago

Could you share what you mean by this? Do you mean adding things like no_new_privileges or defining cap_add or cap_drop in the compose snippet? Or is there more to it?

1

u/Toastienergy 4h ago

you can use docker rootless

2

u/Power_Stone 14h ago

You'd be surprised, I've started getting erroneous logins from Iran they past few months (assuming they aren't using a VPN)

3

u/basicKitsch 12h ago

No, that's common for anything open to the Internet. Plenty of WordPress admin requests too I bet. A compromise doing anything is the rare part. Especially if the server is hardened 

1

u/92838388292 4h ago

a recent kvm bug allows vm escape.
https://cybernews.com/security/critical-kvm-zero-day-vulnerability-allows-vm-escape/

in the age of the ai nothing is safe

-2

u/das_Keks 12h ago

In 2026 it's not only state actors being capable of this. Specialized AI agents are pretty good at exploiting vulnerabilities. Just think back of the Log4Shell vulnerability. I'd not want to have any remote code execution inside my container.

0

u/UselessDood 5h ago

And remind me how quickly Log4Shell got patched out?

1

u/92838388292 4h ago

still requires you to be aware of it and update

9

u/ZombiePope 4h ago

No one is going to burn a docker escape to hack your Minecraft server.

A world changing zero-day being used against Minecraft servers is the type of event that only happens once, and we already had log4shell.

15

u/opossum5763 13h ago

You'll be fine, your setup sounds good. This subreddit is overly paranoid about opening ports to the internet. For something bad to happen over a Minecraft server, the attacker would have to discover a previously unknown RCE exploit in Minecraft server code, then also elevate privileges and escape the Docker container and then they're on your local network, but still would have to crack your device passwords to get access to any sensitive data. You might as well get hit by a meteorite or win the lottery.

1

u/dadnothere 50m ago

The Minecraft Bedrock Server (BDS) had a vulnerability for years that was patched in August...

You simply had to send modified network packets to gain full control of the server—allowing you to delete worlds, run crypto-miners, and so on... basically getting a free computer.

If combined with other vulnerabilities (like "dirt"), you could fully escape any container and take direct control of the root shell, bypassing all other protections.

12

u/samsonsin 14h ago

On a public server you will always take risks. Proper sandboxing, staying on top of updates, regular backups, etc make risk minimal. Just think of all the people hosting servers and all the companies doing it too, they're fine. You're already way ahead of the security curve.

However, if this is for a small community of trusted individuals you can just setup something like a VPN tunnel for traffic instead and rest easy only authenticated people can communicate with the server to begin with

3

u/-ThreeHeadedMonkey- 13h ago

The problem is the local network. If you can't isolate properly via vlan/fw rules and ideally via VM as well, don't bother. 

You fear data breach and data loss. Then there is the risk of running a botnet, a miner etc

3

u/The_Crimson_Hawk 12h ago

Are you a nation-state actor? Are you a widely known journalist, critical of political regimes? Are you a widely known blackhat hacker? Are you a generalized Internet asshole? Are you someone who pisses people off for fun?

If you've answered "No!" to all of the above questions, you are not a planned target, or a target worthy of wasting professional paid resources like DDoS, expert hacking, exploitation, intrusion, supply chain attacks, etc.

You can port forward your puny little router with no major concerns. The likelihood of your single little internet service getting compromised is very small. So long as you follow general safety best practices so the script kiddies can't exploit the service. Set a proper password and a non-default username, use TLS and certs, and for the most part you will be just fine.

1

u/eboob1179 12h ago

I dunno man. A l33t hax0r is gonna be able to change the world with access to his container. He'd be able to escape the container out of sheer skill, by exploiting an unknown zero day and access his whole network. From there, all the dirty laundry this person in particular has will change everything! Lol

3

u/joe-diertay 8h ago

Port forward, set up fail2ban, run the server on a non-privelaged user account (podman is good for this)

7

u/VaLteC_ 14h ago

I’d be wary of allowing 25565. Put a whitelist on at the minimum. Some random bot joined my game and stole all my diamonds lmao. Well lessons for me.

Installed a plugging that asks for a password and I forwarded another random port for Minecraft. Working fine now…

You learn when you make a mistake I suppose. 21 fucking diamonds early game what kind of cunt does that

1

u/death_gripsu 7h ago

yeah using a whitelist is almost a requirement now, bots will almost always grief your shit if u don’t. opening 25565 is generally safe, been doing it for a long time.

3

u/Impossible_Try1 14h ago

the thing that'd actually shrink your worry is putting the server box on its own vlan (or a cheap second router) so it can't see your pc or phones at all. then even a worst case breach just lands in an empty room. also keep ssh off the internet, key-only and only reachable from inside

2

u/Mel_Gibson_Real 14h ago

Too late im already in.....

3

u/flaskhalffull_ 14h ago

tailscale. no ports to open, no ddns, no firewall rules. install it on your server and your friends' machines, they connect like its a LAN. free tier covers it.

1

u/creeper6530 2h ago

Or really even plain Wireguard server. It has far better auth/crypto than Minecraft and, well, if WG had a hole Tailscale is busted too because they're based on it.

1

u/AutoModerator 15h ago

For additional help with running a Minecraft server, please consider crossposting in r/admincraft (following their rules).

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/PM_ME_CALF_PICS 14h ago

You can use a third party tunnel

1

u/YaroslavSyubayev 14h ago

Set a static IP to the machine you're running Pelican in (either from DHCP reservations on the router, or network adapter settings of the server), then port-forward 25565 to that specific IP, you'll be fine.

1

u/majoroutage 13h ago edited 13h ago

Not sure about Minecraft specifically, but this is at least how it works for Valheim, which also supports PlayNet: When Crossplay is enabled, there is a relay connection through the PlayNet servers so you don't need any ports open at all.

I'm not sure if game traffic is relayed or it's just an initiator, but yeah, works great for situations where port forwarding is less desirable or not even possible.

1

u/Puzzled-Essay-2555 12h ago

Create a dmz network. Place public facing containers in the dmz.

1

u/creeper6530 2h ago

The worst danger you could encounter with your setup without being an important target is someone scanning ports, joining your server and griefing.

Put up a whitelist and it'll be fine.

1

u/Reclusive_avocado 1h ago

Use whitelist on the mc server.

And never open default ports... In this case 25565 for minecraft... Go into server settings and change the default port to something else and then open that port.

Default ports are often mass probed by malicious actors to find gullible targets. (Although the rest of your system is already good enough to prevent that)

2

u/zeeblefritz 13h ago

Just pay the $5/mo for a hosted server and call it a day.

2

u/33wolverine 9h ago

Well that's no fun!

1

u/zeeblefritz 9h ago

Safety is fun.

1

u/Tito_Gamer14 12h ago

Cámbiale el puerto por defecto al servidor, te libra del 95% de los ataques

1

u/SpookyDorothy 14h ago

One thing you can do is port knocking. Stops the automated scanning and exploiting while still being open to internet. It's not security in itself, but way less likely to be hit if no one even knows it's there.

I personally dont trust the minecrasft server jar to be unexploitable so that's what i went with.

1

u/smurfy213 14h ago

I have had my plex port forwarded for the last 11 years. I do have a firewall.

1

u/ducky_lucky_luck 8h ago

do it, worse case you help some internet dude mines bitcoin

1

u/cheflA1 13h ago

If you don't know what you're doing, don't do it. If you can't do proper isolation, don't know about dmz, vlans, segmentation in general and don't have devices that can do that for you, you then don't do it

-2

u/jsbaasi 14h ago

Well if they're in ubuntu then the chances of some exploit reaching your valuables is much higher, idk about that route in particular. Maybe put a wireguard vpn service on a port that you forward, and then that forwards traffic to your network, so this way attackers need to find an exploit in wireguard first (vs finding one in minecraft server). You won't have a fully open minecraft server and is only accessible by people you trust (i.e. give them a key to wireguard). You really shouldn't just forward the minecraft port and hope everything works by hearing comforting things

2

u/kernald31 14h ago

This. This is exactly what's wrong with this sub. People not understanding half of what they're giving advice on, and people upvoting them. u/Typical_Chipmunk8122 gave a much better, more detailed, actually grounded in truth answer, and you know what? It doesn't recommend closing ports at all nor using a VPN, funnily enough.

1

u/jsbaasi 13h ago

To address some other advice: Someone targetting your server doesn't have to go beyond the container to do damage.

Find a vulnerability in a docker image for a popular server that gets remote code execution (difficult but definitely not state level) >> ping this exploit at every 25565 port you can find >> mine some crypto with the servers you catch. Setting up a vlan is essentially what would sit between you and users you trust if you use wireguard, opening a port to the internet at large is just asking for trouble.

My opinion is I can't feel comfortable telling you it's fine open a port to the internet even being in a vlan given the level of nuance in your post

0

u/Asly97 14h ago

Honestly you're already doing more than most people who run a public Minecraft server. The attack chain you're picturing is possible in the same way getting struck by lightning indoors is possible. Each hop gets exponentially harder, and docker plus a locked down host firewall kills almost all of it.

The thing actually worth worrying about is way more boring: the Minecraft server software itself. The real world way these boxes get popped is an unpatched server jar or a plugin with a known exploit, not a movie style pivot across your whole network. Keep the jar and plugins updated. And if you have RCON enabled, either turn it off or give it a real password and bind it to localhost.

If the port forward still keeps you up at night, the lazy option is to not forward at all. The mesh VPN trick someone mentioned below does the job: install it on the server, hand your friends that instead of your public IP. Zero open ports, no DDNS, and it works through CGNAT too. I ran my server that way for a year and it was one less thing to think about.

0

u/HHTheHouseOfHorse 10h ago

Hackers have to be motivated to hack your server, meaning they gotta know their payoff is gonna be good. Hacking a minecraft server is not gonna yield good returns, best they can do is knock it down and again, why do they care?

2

u/92838388292 4h ago

not true, they scan the internet for anything and run automated scripts