3 ms·
I launched the Postgres Docker image on a VPS several years ago, published the port on the open Internet, and ... used strong passwords? I still haven’t been c
by williamjackson 6y ago
I launched the Postgres Docker image on a VPS several years ago, published the port on the open Internet, and ... used strong passwords?
I still haven’t been compromised. Have I done something wrong?
- 2mol 6y agoWho knows! That's my struggle with security, unless you have good monitoring in place it's not even trivial to notice problems. In my case I was only made aware of the compromised VM because my hosting provider sent me very stern email about my server's IP netscanning their entire fricking address range.
- rfoo 6y agoHow about try setting up a box with exactly same steps that you would do for your database instance except actually installing the database? Yes, please include all the steps that you may consider "irrelevant without a database installation", they may well be important. Then see if it got compromised.
- capitol_ 6y agoI guess that the docker image doesn't use TLS for connections, or if it does it doesn't use certificates from a CA. This means that your data either goes in plain text over the network, or might be vulnerable to a MITM attack (if you don't manage your certs correctly). I also guess that you don't use SCRAM as the password hashing method, but rather MD5. That means that if someone is able to listen to the connection, they can do a replay attack using the password hash, as there is only 32 bits of entropy added to the hash from the server side. And once you have managed to do the replay attack you can issue arbitrary sql commands as that user.
- wiredfool 6y agoI think it’s probably simpler than that, there are some docker Postgres image that are setup by default to trust connections. Which is ok until about 5 seconds after you open the port to the world.