<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Dr.who virus in my YARN? how to resolve it using firewalld? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297472#M218712</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would still need to secure your cluster since any user can be impersonated in a non kerberised cluster.&lt;/P&gt;&lt;P&gt;Refer&amp;nbsp;&lt;A href="https://blog.cloudera.com/how-to-secure-internet-exposed-apache-hadoop/" target="_blank"&gt;https://blog.cloudera.com/how-to-secure-internet-exposed-apache-hadoop/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;for more details on securing your cluster.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jun 2020 13:58:53 GMT</pubDate>
    <dc:creator>paras</dc:creator>
    <dc:date>2020-06-05T13:58:53Z</dc:date>
    <item>
      <title>Dr.who virus in my YARN? how to resolve it using firewalld?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297140#M218616</link>
      <description>&lt;P&gt;Dr.who is running on my CDH 6.3, I've seen its crontab also using YARN user:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-06-03 at 5.57.08 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/27745i625D03C565CD1CA4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-06-03 at 5.57.08 PM.png" alt="Screen Shot 2020-06-03 at 5.57.08 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-06-03 at 5.58.56 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/27746i213254C197A40AED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-06-03 at 5.58.56 PM.png" alt="Screen Shot 2020-06-03 at 5.58.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've already remove the files of this and I want to implement some restrictions using firewalld,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can I block this virus on running on my YARN 8088? do I need to block the 8088 port in all nodes? and what IP addresses do I need to insert for whitelisting? below is my current rules in firewalld:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;public&lt;BR /&gt;target: default&lt;BR /&gt;icmp-block-inversion: no&lt;BR /&gt;interfaces:&lt;BR /&gt;sources:&lt;BR /&gt;services: dhcpv6-client ssh&lt;BR /&gt;ports: 8042/tcp 7191/tcp 2181/tcp 3181/tcp 4181/tcp 9010/tcp 8044/tcp 8041/tcp 8040/tcp 8091/tcp 9091/tcp 9995/tcp 9994/tcp 7184/tcp 7185/tcp 8084/tcp 8087/tcp 9087/tcp 9999/tcp 9998/tcp 9867/tcp 9866/tcp 9864/tcp 9865/tcp&lt;BR /&gt;protocols:&lt;BR /&gt;masquerade: no&lt;BR /&gt;forward-ports:&lt;BR /&gt;source-ports:&lt;BR /&gt;icmp-blocks:&lt;BR /&gt;rich rules:&lt;BR /&gt;rule family="ipv4" source address="195.3.146.118" reject&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your help on this! thanks!&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 10:02:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297140#M218616</guid>
      <dc:creator>Mondi</dc:creator>
      <dc:date>2020-06-03T10:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dr.who virus in my YARN? how to resolve it using firewalld?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297152#M218624</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should set yarn acls to restrict user access on YARN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check if dr.who is part of yarn admin acl configurations in YARN. Remove the user in this case and set dedicated user and groups for yarn access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer&amp;nbsp;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/cm_mc_yarn_acl.html#concept_manage_yarn_ACLs" target="_blank"&gt;https://docs.cloudera.com/documentation/enterprise/latest/topics/cm_mc_yarn_acl.html#concept_manage_yarn_ACLs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also refer&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cloudera.com/t5/Support-Questions/What-is-Dr-who-user-100s-of-yarn-jobs-are-getting-triggered/td-p/68026" target="_blank"&gt;https://community.cloudera.com/t5/Support-Questions/What-is-Dr-who-user-100s-of-yarn-jobs-are-getting-triggered/td-p/68026&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Paras&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;I&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/I&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/I&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 14:02:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297152#M218624</guid>
      <dc:creator>paras</dc:creator>
      <dc:date>2020-06-03T14:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dr.who virus in my YARN? how to resolve it using firewalld?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297156#M218626</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for sharing with us your concerns. I believe you were referring to the thread under [1].&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dr.who is a username used for all unauthenticated users who submit job to YARN. You can be subject to malware attacks when your cluster is not secured and connected to the Internet. Please see [2] on this topic and how to remedy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please always secure your cluster [3]. Make sure you enable authentication for web consoles [4] (securing your UIs). Once enabled, secured web UI will require SPNEGO to be configured on the browser you are accessing it e.g. the YARN Web UI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let us know if you need more information on this topic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you:&lt;BR /&gt;Ferenc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[1]&amp;nbsp;&lt;A href="https://community.cloudera.com/t5/Support-Questions/HDP-2-6-1-Virus-CrytalMiner-dr-who/m-p/197497/highlight/true#M159548" target="_blank" rel="noopener"&gt;https://community.cloudera.com/t5/Support-Questions/HDP-2-6-1-Virus-CrytalMiner-dr-who/m-p/197497/highlight/true#M159548&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[2]&amp;nbsp;&lt;A href="https://blog.cloudera.com/protecting-hadoop-clusters-from-malware-attacks/" target="_blank" rel="noopener"&gt;https://blog.cloudera.com/protecting-hadoop-clusters-from-malware-attacks/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[3]&amp;nbsp;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/security.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/security.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;[4]&amp;nbsp;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/cm_sg_web_auth.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/cm_sg_web_auth.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 14:32:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297156#M218626</guid>
      <dc:creator>Bender</dc:creator>
      <dc:date>2020-06-03T14:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Dr.who virus in my YARN? how to resolve it using firewalld?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297332#M218647</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31607"&gt;@paras&lt;/a&gt; do you think this is now somehow sufficient? only the know users are indicated on the Admin ACL, can dr.who no longer ran a job in my yarn? :&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-06-04 at 1.42.13 PM.png" style="width: 806px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/27881iCC91253EF875C77D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-06-04 at 1.42.13 PM.png" alt="Screen Shot 2020-06-04 at 1.42.13 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 05:44:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297332#M218647</guid>
      <dc:creator>Mondi</dc:creator>
      <dc:date>2020-06-04T05:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dr.who virus in my YARN? how to resolve it using firewalld?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297472#M218712</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would still need to secure your cluster since any user can be impersonated in a non kerberised cluster.&lt;/P&gt;&lt;P&gt;Refer&amp;nbsp;&lt;A href="https://blog.cloudera.com/how-to-secure-internet-exposed-apache-hadoop/" target="_blank"&gt;https://blog.cloudera.com/how-to-secure-internet-exposed-apache-hadoop/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;for more details on securing your cluster.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 13:58:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Dr-who-virus-in-my-YARN-how-to-resolve-it-using-firewalld/m-p/297472#M218712</guid>
      <dc:creator>paras</dc:creator>
      <dc:date>2020-06-05T13:58:53Z</dc:date>
    </item>
  </channel>
</rss>

