A reminder that upgrading your server might shut down parts of the security related components and leave services unintentionally exposed.

Upgrading should not be done without proper filtering of unwanted incoming traffic (via for example a firewall in front of the server).

Here we can see some database passwords and cryptographic secrets exposed during #debian13 upgrade due to PHP being down while the httpd was not.

#infosec #cybersecurity

Database credentials and cryptographic secrets exposed during Debian system upgrade. The secrets have been censored with red blocks.
you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 1 year ago

@harrysintonen@infosec.exchange I hadn't thought of that, good point!

  • source