10
top 4 comments
sorted by: hot top controversial new old
[-] AmbiguousProps@lemmy.today 5 points 1 year ago

People really expose redis to the internet?

[-] kid@sh.itjust.works 3 points 1 year ago

Yes.

303,481 servers worldwide, according to Shodan.

[-] AmbiguousProps@lemmy.today 2 points 1 year ago* (last edited 1 year ago)

😭 why though? I assume that if you are smart enough to setup redis, you'd be smart enough to use VPNs (or similar) as to never expose it

[-] sugar_in_your_tea@sh.itjust.works 2 points 1 year ago* (last edited 1 year ago)

Our prod exposed Redis until I noticed. Apparently we had to reset caches after releases, and our devOPs forgot to remove access to it after creating scripts to handle that.

It happens, but it really shouldn't. At least ours was at a different subdomain (something like app-region-redis.domain.com or whatever).

this post was submitted on 25 Jun 2024
10 points (100.0% liked)

Cybersecurity

7823 readers
143 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS