Slashdot Mirror


Cache On Delivery — Memcached Opens an Accidental Security Hole

jamie spotted this eye-opening presentation (here's a longer explanation) about how easy it is to access sensitive data on many sites using memcached, writing "If you already know what memcached is, skim to slide #17. The jaw-drop will happen around slide #33. Turns out many websites expose their totally-non-protected memcached interface to the Internet, including gowalla, bit.ly, and PBS."

3 of 149 comments (clear)

  1. Re:More Boiled and Distilled. by outsider007 · · Score: 5, Funny

    That's actually more of a feature.

    --
    If you mod me down the terrorists will have won
  2. Re:More Boiled and Distilled. by Farmer+Tim · · Score: 5, Funny

    That's. Why.

    --
    Blank until /. makes another boneheaded UI decision.
  3. Re:A few clarifications by IAmGarethAdams · · Score: 5, Funny

    Mostly through rouge employees

    Luckily, they often get caught red-handed.