4 ms·
I'm not a security expert. I spent a good chunk of time yesterday mitigating this with our security people so I have a decent overview of the bug and how it's e
by markbnj 5y ago
I'm not a security expert. I spent a good chunk of time yesterday mitigating this with our security people so I have a decent overview of the bug and how it's exploited. If you aren't running an application on your home server or phone that others can connect to from outside your network then this isn't likely an issue for you. Take this as inexpert guidance until someone more authoritative chimes in. The vector of vulnerability here is user content getting into log messages, as can happen if you log headers from user connections for example.
- cesarb 5y ago> If you aren't running an application on your home server or phone that others can connect to from outside your network then this isn't likely an issue for you. The direction of the connection isn't relevant. For instance, when you are playing Minecraft and connect to a server, the connection starts from inside your network, but could be used to attack your Minecraft client.
- VectorLock 5y ago>others can connect to from outside your network Doesn't exactly cover it. Strings, uh, find a way.
- reginaldo 5y agoActually, the surface of attack is larger. It is: the machine receives strings from a service that's been connected to the internet somehow and the machine itself server can connect to the internet. A non-obvious example would be logs/data that will be processed by Solr.