PDA

View Full Version : Cache On Delivery mdash; Memcached Opens an Accidental Security Hole


sl4shd0t
08-07-2010, 06:15 AM
jamie spotted this eye-opening presentation (here's a longer explanation) about how easy it is to access sensitive data on many sites using memcached, writing "If you already know what memcached is, skim to slide #17. The jaw-drop will happen around slide #33. Turns out many websites expose their totally-non-protected memcached interface to the internet, including gowalla, bit.ly and PBS."pa href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fit.slashdot.org%2Fstory% 2F10%2F08%2F07%2F035255%2FCache-On-Delivery-mdash-Memcached-Opens-an-Accidental-Security-Hole" target="_blank" title="Share on Facebook"img src="http://a.fsdn.com/sd/facebook_icon_large.png"/a a href="http://twitter.com/home?status=Cache+On+Delivery+%26mdash%3B+Memcache d+Opens+an+Accidental+Security+Hole%3A+http%3A%2F% 2Fbit.ly%2F9nh5wc" target="_blank" title="Share on Twitter"img src="http://a.fsdn.com/sd/twitter_icon_large.png"/a/ppa href="http://it.slashdot.org/story/10/08/07/035255/Cache-On-Delivery-mdash-Memcached-Opens-an-Accidental-Security-Hole?from=rss"Read more of this story/a at Slashdot./ppa href="http://feedads.g.doubleclick.net/~at/QE0_kz1iesuDvWRNI-hsIUOUdlg/0/da"img src="http://feedads.g.doubleclick.net/~at/QE0_kz1iesuDvWRNI-hsIUOUdlg/0/di" border="0" ismap="true"/img/abr/a href="http://feedads.g.doubleclick.net/~at/QE0_kz1iesuDvWRNI-hsIUOUdlg/1/da"img src="http://feedads.g.doubleclick.net/~at/QE0_kz1iesuDvWRNI-hsIUOUdlg/1/di" border="0" ismap="true"/img/a/pimg src="http://feeds.feedburner.com/~r/Slashdot/slashdotDevelopers/~4/s1Bq2uR_Yus" height="1" width="1"/

More... (http://rss.slashdot.org/~r/Slashdot/slashdotDevelopers/~3/s1Bq2uR_Yus/Cache-On-Delivery-mdash-Memcached-Opens-an-Accidental-Security-Hole)