• Blackmist@feddit.uk
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 days ago

    I did this just to reduce network latency. It’s not for public use, and tbh, I don’t think you can even get at it from outside the VPN.

      • Blackmist@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        I haven’t been down to test their public wifi in the cafe to see if that can access it.

        The guy who installed it used to work for us and is a known clown, so it’s entirely possible.

        Although if it is, there’s way worse things they can do from there. Like connect to the actual database for a start.

        • luciferofastora@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          18 hours ago

          Does the database use the same authentication and permissions as the API? If the API authenticates against the DB with a technical user, it may be still be an exploitable vulnerability for people who can’t access the DB directly but can access the API. I don’t know what database it is, what other databases run on the same server and what privileges might be achievable or escalatable, but generally “there are worse weaknesses” isn’t a solid security policy.

          You could give me a VPN access and I’ll take a look around :p

          (Please don’t, actually – in case it needs to be said, running pentests on prod is a dangerously bad idea already even before we get to the whole “trusting a stranger on the Internet just because they sound sorta knowledgeable” issue)