923 Clawdbot gateways are exposed right now with zero auth (they just connect to your IP and are in)
That means shell access, browser automation, API keys.
All wide open for someone to have full control of your device.
Had Clawdbot check my setup:
- Config shows bind: "loopback"
- External port test: connection refused
(Not exposed)
If you're running Clawdbot, check yours:
bind: "all" means you're on that list
Fix: change to bind: "loopback" and restart.
It takes 10 seconds.
RT for exposure
Clawdbot is awesome 🦞
But I just checked Shodan and there are exposed gateways on port 18789 with zero auth
That's shell access, browser automation, your API keys
Cloudflare Tunnel is free, there's no excuse
RT to save a ClawdBot from getting cooked