ElasticSearch Cloud-Azure Insecure Transit

Discussion in 'News Aggregator' started by Packet Storm, 20 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    The connection string for ELK cloud-azure plugin contains hardcoded http url with the lack of encryption and certificate validation, therefore it is prone to sniffing and MiTM attacks. A potential attacker with the required access to the network traffic would be able to intercept the content of the indexes snapshots.

    Continue reading...
     

Share This Page

Loading...