3 ms·
Put machines with sensitive data on a private network. Have one machine/one set of machines connected to both the private network and public network that proxy
by btmorex 9y ago
Put machines with sensitive data on a private network. Have one machine/one set of machines connected to both the private network and public network that proxy requests to the data machines. Proxy by parsing original request and then rewriting (i.e. don't just pass along the request). Rate limit and implement notifications on data machines so that if the proxies are compromised, the attacker can't easily do a full data dump. Don't allow remote administration only physical (this rules out this architecture for most companies, but honestly, not a company like equifax with incredibly sensitive info and where network locality is not a big issue).
- btown 9y agoTo the remote administration point, if you have this architecture and still open up the private data-network to remote SSH connections, you're at least limiting the attack space to vulnerabilities in SSH and the network stack/firewall on your ingress server, but not vulnerabilities in the application server. Much better than nothing.
- rmrfrmrf 9y agoIf you look at the CVE, it's literally plain shell commands as strings in the Content-* headers. These commands would appear to be local with whatever user the app is running as.
- kelnos 9y agoAnd that's the ridiculous thing: this is actually a fairly easy thing to protect against. Why the hell did the webapp servers have direct access to the database? If there was a service in the middle mediating requests, that would have been another line of defense. Sure, maybe _that_ service might have holes, but it'd be another hurdle the attacker would have to clear.
- rmrfrmrf 9y agoAs long as JNDI is a best practice in Java land, I'd say that the majority of Java app servers are directly connected to databases.
- kelnos 9y agoIs it? I've been doing Java on and off for nearly a decade (with a brief foray into it in the early 2000s) and I had to look up what JNDI is.