4 ms·
> Just been hacked through this method and cannot believe > ... that they don't even MENTION the security > concerns from the quickstart guide> > http://redi
by greyboy 11y ago
> Just been hacked through this method and cannot believe
> ... that they don't even MENTION the security
> concerns from the quickstart guide>
> http://redis.io/topics/quickstart http://redis.io/topics/quickstart
??
Like the 'Securing Redis' section from that link?
Securing Redis
==============
By default Redis binds to all the interfaces and has no authentication at all. ...
1) Make sure the port Redis uses to listen for connections is firewalled...
2) Use a configuration file where the bind directive is set ... [to] as little network interfaces you are using...
3) Use the requirepass option ...
4) Use spiped or another SSL tunnelling software...
- mikecmpbll 11y agoantirez added that section after I mentioned that it was lacking on the comments section of this article, see http://www.antirez.com/news/96#comment-2351969000 http://www.antirez.com/news/96#comment-2351969000