Skip to content

Locked down by default #15

@simonw

Description

@simonw

The plugin currently accepts any incoming JSON by default, under the expectation that you'll initially be running it on a laptop. The README shows how to secure it.

https://www.bleepingcomputer.com/news/security/new-meow-attack-has-deleted-almost-4-000-unsecured-databases/ reminded me that MongoDB and Elasticsearch are open by default, with the result that people keep on deploying unprotected instances.

So by 1.0 of this plugin I'm going to figure out how to have it secure by default.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions