Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah - kinda crazy theres no auth by default AND eval is allowed. Pretty trivial for someone to have it download a script and run it pretty much with free reign.


Redis doesn't accept unauthenticated external connections by default for a while now, specifically to try and eliminate this footgun.

https://github.com/redis/redis/commit/edd4d555df57dc84265fdf...


I had an issue where I used the redis docker image and didn't understand docker networking properly so I set the network mode as host so my other container could connect. Not knowing this had exposed redis to the world unauthenticated (in about 2018).

Eventually a kind script set a password on redis which caused me to notice and fix this issue.


Interesting, this definitely happened with a more recent version... Wonder if theres some other exploit at play too (could also be the containerized version?)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: