Secure your MongoDB, Redis, etc
medium.com
medium.com
---
FYI, there isn't a security vulnerability in that wretched example... just WTFibility.
(I'm assuming shell escaping...else virtually every query wouldn't work.)
Nothing surprises me.
Short of that I find redis an nice piece of software, I only wish it was somewhat more sane in its default configuration.
In practice, however, I have seen far too many developers spend hour after hour trying to unwind a byzantine labyrinth of iptables and strange network configurations, weird firewall rules and corporate policies, never mind mangled DNS, to think that the correct solution is merely "secure defaults".
At the end of the day, developers get paid to "make it work" and unfortunately that strongly incentivizes the "open by default" configuration mindset.
A few example scenarios where this can happen: one may open a port temporarily in testing before something goes live and forget to close it back up. Legacy applications may be dependent on certain services at certain ports and it may not be trivial to change those, or even add authentication to them. The whitelist rules allowing communication can get mangled or misconfigured, especially if the legacy application's IP jumps around; in frustration, an admin may set the rules too wide to try to encompass all potential IPs, assuming that no one in the same /16 is going to try to break in soon and they'll come back and fix this in like a week or something. One may spin up a test instance into a wide-open security group and assume that someone else is going to come through and sweep it up, and before you know it that test instance is hosting real data and no one has tried to clamp it down, or that firewall rules for that port are not necessary because the authentication/whitelisting will occur on the software side, and then fail to set that up correctly, or run an insecure version of the software.
There's that old saying: "A person isn't stupid; people are". The constraints of the business often make it so that compromises have to be made and what we'd consider a "good solution" is politically intractable. No one likes that, but it's the environment many of us have to work in, like it or not.
All we can do is scream at the wall until at least one exec goes through a traumatic security event. It usually takes a significant breach to scare the exec team straight.
If you're using the version of redis packaged in trusty/universe, it is extremely old and doesn't contain this. It also contains a handful of critical security vulns that are being openly exploited in the wild. Update manually TODAY.
i don't think people want run the database or the cache system or any other critical service as public, but probably the background is not enough to solve issues on production when they pops up so:
1. you deploy a service over cloud 2. everything works 3. but if something must be solved at infrastructure level 4. apply('old style solution') open everything and debug from home attached to production
https://blog.steve.fi/Secure_your_rsync_shares__please_.html
People never knew how to deploy software.
Are there even guides to learn that? Seems not.
It's network isolation or you will be owned.
http://blog.binaryedge.io/2016/10/07/internet-security-expos...
(But let's say binding on 0.0.0.0 or not having a firewall in the system are not only their fault)
In the same way people can trust local addresses in Pgsql
Or why enable flags that allow to loose data without warnings in many common circumstances?
Don't expect anything from mongo. Don't trust mongo. Don't use mongo.
Is it viable to use an SSH tunnel with each service listening on localhost alone and using an encrypted tunnel to send data?
If you're running it over the public 'net, then I think Mongo and Redis allow for username/passwords and/or encrypted transit.
The why is left as an exercise for the reader.
Professional non-trivial usage should be on AWS/Google/Azure/SoftLayer.
And they're certainly better than trying to run that on someone's home DSL connection.
I run my personal server on DigitalOcean and it has been pretty good. At work we run a series of tier-2 services on DO and it's been great for our use cases. We used to run a cluster of 100 machines there and it was stable and cheap.
I realise it's very simple, and that isn't good for a lot of production services, but I don't understand the hate?