https://ari.lt/mblog/post/540
Uncategorized
1
Posts
1
Posters
0
Views
-
the nginx RCE bug is so overplayed
it requires ALSR disabled and even then its not guarenteed considering how many servers run alpine with musl
i guess theres the risk of a DoS still but, although fail2ban & rate limiting greatly mitigate this risk
just use ufw or some other FW, alpine ( if possible ), fail2ban, ensure to drop worker process permissions, and keep your server up to date -
R relay@relay.infosec.exchange shared this topic