R
Railwayβ€’12mo ago
macwilko

Odd logs coming up in Redis

1:M 14 Dec 2023 15:00:33.775 # Possible SECURITY ATTACK detected. It looks like somebody is sending POST or Host: commands to Redis. This is likely due to an attacker attempting to use Cross Protocol Scripting to compromise your Redis instance. Connection from 192.168.32.4:17944 aborted.
1:M 14 Dec 2023 15:00:33.775 # Possible SECURITY ATTACK detected. It looks like somebody is sending POST or Host: commands to Redis. This is likely due to an attacker attempting to use Cross Protocol Scripting to compromise your Redis instance. Connection from 192.168.32.4:17944 aborted.
@Brody @Vin
23 Replies
Percy
Percyβ€’12mo ago
Project ID: dd3f96f7-3ab3-4453-86a3-32328b2f81d6
macwilko
macwilkoOPβ€’12mo ago
dd3f96f7-3ab3-4453-86a3-32328b2f81d6 is there a way to determine what
192.168.32.4:17944
192.168.32.4:17944
was ?
Brody
Brodyβ€’12mo ago
that's a local address, likely the dashboard trying to connect
macwilko
macwilkoOPβ€’12mo ago
for reference, I haven't connected via any redis client that's strange, you mean the railway dashboard?
Brody
Brodyβ€’12mo ago
yeah, that's my guess, but whatever it is, it's a local address so it's not an attack
macwilko
macwilkoOPβ€’12mo ago
idk strikes me as very strange if it's caused by the railway dashboard, woudln't that be easy to determine?
Brody
Brodyβ€’12mo ago
do you have the tcp proxy enabled?
macwilko
macwilkoOPβ€’12mo ago
you mean, exposed to the public web?
Brody
Brodyβ€’12mo ago
I mean do you have the tcp proxy enabled on the redis service
macwilko
macwilkoOPβ€’12mo ago
(it was previously) i'ved turned it off not sure what that is (tcp proxy)
Brody
Brodyβ€’12mo ago
you definitely know what it is
macwilko
macwilkoOPβ€’12mo ago
No description
macwilko
macwilkoOPβ€’12mo ago
(there was previously a generated domain ... which I could use to connect to it outside railway) i turned it off now
Brody
Brodyβ€’12mo ago
that would be a tcp proxy
macwilko
macwilkoOPβ€’12mo ago
right πŸ˜„
jr
jrβ€’12mo ago
If you don't have the tcp proxy enabled Railway will attempt to make a request to the open port (in this case 6379) so that we can suggest adding a domain if necessary.
Brody
Brodyβ€’12mo ago
mystery solved
macwilko
macwilkoOPβ€’12mo ago
hey, when this error happened, the tcp proxy was enabled. It was something like viaduct.proxy.rlwy.net:49184
Brody
Brodyβ€’12mo ago
mac, its a local address
jr
jrβ€’12mo ago
Oh just checked and turns out we make the request regardless
macwilko
macwilkoOPβ€’12mo ago
ok πŸ™‚
jr
jrβ€’12mo ago
I’ll raise with team though. Seeing that message in the logs is very cryptic indeed
macwilko
macwilkoOPβ€’12mo ago
yes, am i the first to notice it? It's a little odd looking.
Want results from more Discord servers?
Add your server