Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough (wiz.io)
10 points by timmclean on Nov 12, 2021 | hide | past | favorite | 2 comments


The whole thing is just astounding. C# host process as root, iptable network rules in the container instead of outside of it, servers not validating client certificates. My oh my.

How any of this made it past security and production review is beyond me. Unless there wasn’t any.


Wow.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: