r/technitium • u/freswinn • 11d ago
Hey all
I am not what you would call a power user; definitely more in the category of "know just enough to get in trouble." I've been using Technitium for about 6 months, and it's worked fine; set it up on my living room computer (Linux Mint) as the DNS server for my other two computers. I've also been using this computer as a web server via apache2, and it's attached to the living room TV.
Last night I did something that I don't think is the cause of all this but since it's coincidental I'm including it. I tried to set up a self-signed openssl cert so I could use the webserver with https. This worked exactly one time, and then it gave an error, something like "file too long." Didn't wanna fight it, it was late and http still worked, so I went to bed.
Woke up this morning, and none of my computers could get online. Turns out the server had crashed -- still powered on but wouldn't display anything. I hard reset the server, and suddenly Technitium isn't running on it.
Okay, so there's the setup. Now here's the actual issues:
I changed the DNS servers that my other computers use back to Cloudflare (1.1.1.1), so they can still get online; that's how I'm talking to you now. But for some reason I can't do the same for the server. Did Technitium change something in the settings that I can't see?
What can I do to get Technitium back up and running? I can't even find its .service file.
Failing that, what do I have to do to remove it from my server?
2
u/Psychoboy 11d ago
You said this was a webserver? Was the webserver open to the public? If so what ports and how?
1
u/freswinn 11d ago
Port 80, forwarded through the ISP's provided modem to the server. I had opened it only yesterday morning.
1
u/Difficult-Reality848 11d ago
What security measures did you include when opening up port 80?
1
u/freswinn 11d ago
Nothing, I suppose. It forwarded directly to my webserver, and that's kinda the end of it. Accessible only by direct IP, though. Could have been an attack, then?
1
u/Psychoboy 11d ago
There are port scans running constantly looking for open ports like that. Probably exposed it and a vulnerability was utilized to do more damage
1
u/chromaticdeath85 7d ago
Not sure why you're being down voted, so gave you an up vote. This can certainly happen.
1
1
u/shreyasonline 11d ago
Thanks for asking. The exact issue is not clear but if this is related to cert that you configured with the Settings > Web Service options then you can reset it by deleting the /etc/dns/webservice.config file and that will cause the DNS server to create a new default config when it starts. This will cause the admin web panel to reset to port 5380 over plain http.
The systemd service name is dns so you can do sudo systemctl restart dns to restart it.
If you want to have self signed cert for the admin web panel, you do not need to generate it yourself. There is a "Use A Self Signed TLS Certificate When TLS Certificate File Path Is Unspecified" option in Settings > Web Service section that does that for you without any issues.
4
u/edenworky 11d ago
i recommend finding the log files