{"id":17999,"date":"2021-06-29T22:54:20","date_gmt":"2021-06-29T20:54:20","guid":{"rendered":"https:\/\/tuxproject.de\/blog\/?p=17999"},"modified":"2021-06-29T22:54:20","modified_gmt":"2021-06-29T20:54:20","slug":"scheunentor-ueberraschend-durchschossen","status":"publish","type":"post","link":"https:\/\/tuxproject.de\/blog\/2021\/06\/scheunentor-ueberraschend-durchschossen\/","title":{"rendered":"Scheu\u00adnen\u00adtor \u00fcber\u00adra\u00adschend durch\u00adschos\u00adsen"},"content":{"rendered":"<p>Was pas\u00adsiert, wenn man eine Daten\u00adbank ohne Pass\u00adwort\u00adschutz offen im Inter\u00adnet zur Ver\u00adf\u00fc\u00adgung stellt?<\/p>\n<p>Nun, jemand wird sie fin\u00adden <a href=\"https:\/\/blog.newsblur.com\/2021\/06\/28\/story-of-a-hacking\/\">und benut\u00adzen:<\/a><\/p>\n<blockquote><p>When I con\u00adtai\u00adne\u00adri\u00adzed Mon\u00adgoDB, Docker hel\u00adpful\u00adly inser\u00adted an allow rule into ipta\u00adbles, ope\u00adning up Mon\u00adgoDB to the world.<\/p><\/blockquote>\n<ol>\n<li>Man h\u00e4ngt eine unge\u00adsch\u00fctz\u00adte Daten\u00adbank<\/li>\n<li>in einem \u201eCon\u00adtai\u00adner\u201c (d.h. in einer <em>black box<\/em> ohne direk\u00adten Pro\u00adto\u00adkoll\u00adzu\u00adgang)<\/li>\n<li>offen ins Inter\u00adnet und schreibt dann, dass<\/li>\n<li>\u201eHacker\u201c fre\u00adcher\u00adwei\u00adse die\u00adse M\u00f6g\u00adlich\u00adkeit genutzt haben.<\/li>\n<\/ol>\n<p>Immer\u00adhin habe aber das Ein\u00adspie\u00adlen einer Siche\u00adrungs\u00adko\u00adpie <em>nur vier\u00addrei\u00advier\u00adtel Stun\u00adden<\/em> gedau\u00adert. <\/p>\n<p>Ob das Web wohl wie\u00adder <em>bes\u00adser<\/em> w\u00e4re, wenn es <em>schwie\u00adri\u00adger<\/em> w\u00e4re, einen Ser\u00adver zu betrei\u00adben?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Was pas\u00adsiert, wenn man eine Daten\u00adbank ohne Pass\u00adwort\u00adschutz offen im Inter\u00adnet zur Ver\u00adf\u00fc\u00adgung stellt? Nun, jemand wird sie fin\u00adden und benut\u00adzen: When I con\u00adtai\u00adne\u00adri\u00adzed Mon\u00adgoDB, Docker hel\u00adpful\u00adly inser\u00adted an allow rule into ipta\u00adbles, ope\u00adning up Mon\u00adgoDB to the world. Man h\u00e4ngt eine unge\u00adsch\u00fctz\u00adte Daten\u00adbank in einem \u201eCon\u00adtai\u00adner\u201c (d.h. in einer black box ohne direk\u00adten Pro\u00adto\u00adkoll\u00adzu\u00adgang) \u2026<\/p>\n<p><a href=\"https:\/\/tuxproject.de\/blog\/2021\/06\/scheunentor-ueberraschend-durchschossen\/\" class=\"more-link\">\u2018Scheu\u00adnen\u00adtor \u00fcber\u00adra\u00adschend durch\u00adschos\u00adsen\u2019 wei\u00adter\u00adle\u00adsen \u00bb<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wp_typography_post_enhancements_disabled":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":3,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":""},"categories":[19],"tags":[],"series":[],"class_list":["post-17999","post","type-post","status-publish","format-standard","hentry","category-nerdkrams"],"share_on_mastodon":{"url":"","error":""},"wp-worthy-pixel":{"ignored":false,"public":null,"server":null,"url":null},"wp-worthy-type":"normal","_links":{"self":[{"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/posts\/17999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/comments?post=17999"}],"version-history":[{"count":0,"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/posts\/17999\/revisions"}],"wp:attachment":[{"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/media?parent=17999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/categories?post=17999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/tags?post=17999"},{"taxonomy":"series","embeddable":true,"href":"https:\/\/tuxproject.de\/blog\/wp-json\/wp\/v2\/series?post=17999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}