3 ms·
>Clustering is built into it with security Just to note, distributed erlang is NOT secure AT ALL. You absolutely need your own source of network isolation to
by lightbyte 8y ago
>Clustering is built into it with security
Just to note, distributed erlang is NOT secure AT ALL. You absolutely need your own source of network isolation to keep it secure.
By default the EPMD daemon (that coordinates nodes in a cluster) listens on an open port and accepts node join requests if they contain a correct secret cookie (short authentication string). EPMD has zero protection against brute force attempts to guess a cookie. If your EPMD port is open to the internet it is trivial to gain access to your entire cluster and execute arbitrary code.
See: https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/ https://insinuator.net/2017/10/erlang-distribution-rce-and-a...