Hacker News new | ask | show | jobs
by throwa356262 8 days ago
This will be a busy weekend for all sysadms. This is another redis 0day, this one found by GLM 5.1:

https://xcancel.com/Lyutoon_/status/2080494539513778610#m

1 comments

What kind of utterly useless sysadmin relies on authenticated redis admin surfaces to be memory safe?

What crazy environment requires low priority nothingburger bugs like this to be fixed during the weekend?

One where customers have their own scanners, and their unfounded panic overrides logical analysis by the engineers and admins.

We’ve had to patch plenty of stupid “security” bugs just to satisfy a paying customer.

This is the real answer to the op.

It’s incredible how overblown these sorts of things can become

If the customer can run the scanner and find the vuln, that means they can log in, right? Which means they can RCE.
Not always, it can be run at static code analysis or the container repository (not the prod one)?
I guess an llm is instructed to find an exploit, it finds the one with least resistance. And stops.

Once these are closed, they'll find more