Redis security password

41 views
Skip to first unread message

Richard

unread,
Aug 18, 2016, 12:23:38 PM8/18/16
to web2py-developers
Hello,

Should we leave mention about redis security and how to set password??




# Redis Server need Administrative password to avoid hacking by Linux.lady and Linux.Download.196 trojan
# NOTE: We can't set password from redis-cli because it get overrided by redis.conf
sed -i 's/# requirepass foobared/requirepass "${REDISPASSWORD}"/g' /etc/redis/redis.conf
service redis-server restart

Richard

Niphlod

unread,
Aug 19, 2016, 2:39:12 AM8/19/16
to web2py-developers
"should we leave mention that every site should be serverd only through https only and that sensitive data should be protected by some kind of authentication system" ?
my redis instance listens only on localhost. and that's the way it's supposed to be. 
IMHO comments on the sourcecode will be never read by who is so stupid to publish its redis instance over the net.

Massimo DiPierro

unread,
Aug 19, 2016, 8:26:30 AM8/19/16
to web2py-d...@googlegroups.com
LOL

--
-- mail from:GoogleGroups "web2py-developers" mailing list
make speech: web2py-developers@googlegroups.com
unsubscribe: web2py-developers+unsubscribe@googlegroups.com
details : http://groups.google.com/group/web2py-developers
the project: http://code.google.com/p/web2py/
official : http://www.web2py.com/
---
You received this message because you are subscribed to the Google Groups "web2py-developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to web2py-developers+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Richard Vézina

unread,
Aug 19, 2016, 9:07:22 AM8/19/16
to web2py-d...@googlegroups.com
6000 deployment over 30000

Richard Vézina

unread,
Aug 19, 2016, 9:14:18 AM8/19/16
to web2py-d...@googlegroups.com
I guess this should should be manage at installation by package manager... 

And actually we are talking many time about https in the book...

It just kind to act a reminder as there is a exploit and because package is not properly configured to me.

Richard

Niphlod

unread,
Aug 19, 2016, 10:14:03 AM8/19/16
to web2py-developers
mmmmhhhhh .... http://download.redis.io/redis-stable/redis.conf , line 61. it's perfectly fine.
6000 deployment over 30000

LOL


details : http://groups.google.com/group/web2py-developers
the project: http://code.google.com/p/web2py/
official : http://www.web2py.com/
---
You received this message because you are subscribed to the Google Groups "web2py-developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to web2py-develop...@googlegroups.com.

For more options, visit https://groups.google.com/d/optout.

--
-- mail from:GoogleGroups "web2py-developers" mailing list

details : http://groups.google.com/group/web2py-developers
the project: http://code.google.com/p/web2py/
official : http://www.web2py.com/
---
You received this message because you are subscribed to the Google Groups "web2py-developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to web2py-develop...@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages