Hacker News new | ask | show | jobs
by mcfrankline 3486 days ago
Nope. Not bitcoin.

It's pointed at xmr.pool.minergate.com:45660/xmr

XMR is Monero. It has a lower hashrate so i see how the attacker can make something out of this.

Are you sure it's not an inside job? Cause anyone with access to run this under statd basically owns you right now

1 comments

Yes, it's a Redis vulnerability (caused by bad config on our part) in one container where the firewall was down.

Strange thing if we run 'top' from the main host, all containers running redis say 'statd' as their user; inside the container the user showed 'redis'. We removed nfs and all related files, and now it shows a user ID number. Is this something we should worry about?

Could you elaborate what redis configuration could've caused this?
FYI: Default redis install has since fixed this vulnerability.