Uploaded image for project: 'Kudu'
  1. Kudu
  2. KUDU-1875

Refuse unauthenticated connections from publicly routable IP addrs

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.2.0
    • 1.4.0
    • rpc, security
    • None

    Description

      Kudu should by default not accept unauthenticated connections from publicly routable IPs, even if authentication and encryption are not configured. An unsafe flag should be provided to enable unauthenticated connections from publicly routable IPs, with appropriately scary verbiage and a link to https://krebsonsecurity.com/2017/01/extortionists-wipe-thousands-of-databases-victims-who-pay-up-get-stiffed/.

      Attachments

        Activity

          People

            hahao Hao Hao
            danburkert Dan Burkert
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: