Is it normal that I see others’ Redis data on shared hosting?
stackoverflow.com
stackoverflow.com
> In addition, it is necessary to specify a CA certificate bundle file or path to be used as a trusted root when validating certificates.
... will not cause many real users to do what they actually need to do here. That's certainly the experience with lots of software that has this sort of feature. Users tend to fill this out with the CA certificate corresponding to the server. Now, if what you've done is spin up your own CA just for Redis, mint a certificate for the server and then you're going to do the same for all clients this could work (it'd be weird but it could work) but just as likely you'll use a nice Let's Encrypt certificate for the server - and now you're telling the server "By the way, anybody with a Let's Encrypt cert is trusted as a client". This is, let's say, very unlikely to be what you actually wanted.
(Edit: Clarified text above somewhat)
This is how it works with zookeeper and kafka as well. I don't know why those projects are such a pain in the butt but I certainly don't want to learn two completely different over complicated authentication systems when all I really wanted is the ability to set a password. I'll just use TLS for authentication and be done with it.
TLS authentication isn't that hard once you understand the fundamentals.
“ Potentially is just your own DB being exposed and now being utilized by someone else (such as hosting a covert/malicious site)... I had this happen once when accidentally left a testing (non-production, no real data/usage) redis server exposed on the internet. Came back in a couple days to find it full of someone else's data.”
Also: the Internet is big enough for people to exist who do it "just for fun".
In either case this makes no sense at all.
Oh my, I can already see storm the provider will get on social media once we find out who's such a moron.
Also I bet there's someone unethical who's right now going through all Redis hosting services trying to repro this and get some data.
I wouldn't blame the hosting provider alone unless they explicitly marketed that shared Redis as something being available. Presumably it's just there because of a misconfiguration and since it doesn't hurt anyone nobody noticed or bothered to turn it off.
I don't know why they'd offer a publicly accessible redis other than for testing maybe, but if they communicate it, it's on the user.
"Is it normal?" is kind of a nonsensical question without any further context.
There are basically people doing this continuously in a loop. Open up port 3306 and watch people trying to connect to your MySQL instance with common passwords. IPv4 addresses are easily enumerable and the bad guys already thought of everything. (I put a real MySQL there once; they deleted all the tables and created a new one asking for bitcoin to get them back.)
I know MySQL is not Redis but the same principle applies; someone is scanning you for open services right now.
Database ransomware: Are you vulnerable - Next year on Scareware Conference.
I remembered a few hours later, gone back to rebuild the machine as I assumed it would be compromised, and sure enough, there was some crypto miner on it. Sadly for them, the machine didn't have anywhere enough processing power to make it worth it and they should've instead been smarter and made better use of it (it had a very beefy network connection so plenty of potential for DoS attacks or hosting malicious content, as well as being in a privileged position to capture potentially sensitive unencrypted traffic).
Our base image now comes with a hardened sshd and raised firewalls so the first provisioning-run of the configuration management actually has to reduce the firewall protection.