> WTF does that mean?
The website assumes that if you dropped by or googled the vulnerability, it's because you had saltstack exposed to the public internet.
You don't have to react so harshly to that turn of phrase.
> WTF does that mean?
The website assumes that if you dropped by or googled the vulnerability, it's because you had saltstack exposed to the public internet.
You don't have to react so harshly to that turn of phrase.
> Even if you didn't notice any unexpected symptoms, please: nuke and restart.
If I were writing this, I'd probably write something like "On May x, a remote-code-execution in (all versions?) public salt-masters (not minions?), was unveiled. Shortly thereafter, actual exploitation in the wild is being used. If your salt installation uses a salt-master, and it's internet-reachable, it may already be compromised, along with much your infrastructure. Section 2 is how to see if you are infected, and Section 3 is how to remove the infection."
That's much worse. That implies there is a reliable way to detect and remove the infection. That's not the case. This website included some known attacks and such. There's a high chance that there were attacks of this vulnerability with additional payloads.
There's no way to know if you were hit with a rootkit that persists itself in the bootloader or other parts of your system. There's no way to know if you were infected or not.
The only way to be sure is to nuke the machine, as they said.
Security advice should always err on the right side for a naive reader.