Vitess security auditthreat model was also a force-multiplier for the fuzzing work that led to the discovery of a few missed edge cases when fixing the two CVEʼs. The audit started with a meeting between Ada Logics, the Vitess No Actor with local network or local file access An actor that has breached some security boundaries of the environment to get to the position of having access to the local network or file system. Yes attacker who has compromised the machine running VTAdmin may escalate privileges by listening on the network. For example, VTAdmin-api connects to Vtctld over GRPC. At this stage the request is already authenticated0 码力 | 41 页 | 1.10 MB | 1 年前3
The Vitess 11.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 362 Ports and Network interactions in Vitess 362 Reparenting . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically0 码力 | 481 页 | 3.14 MB | 1 年前3
The Vitess 10.0 Documentation
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 340 Ports and Network interactions in Vitess 340 Reparenting . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically0 码力 | 455 页 | 3.07 MB | 1 年前3
The Vitess 12.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 119 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 404 Ports and Network interactions in Vitess . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically0 码力 | 534 页 | 3.32 MB | 1 年前3
The Vitess 9.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 86 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically availability zone. Vitess gracefully handles cell-level failures, such as when a cell is cut off the network. Each cell in a Vitess implementation has a local topology service, which is hosted in that cell0 码力 | 417 页 | 2.96 MB | 1 年前3
The Vitess 6.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically availability zone. Vitess gracefully handles cell-level failures, such as when a cell is cut off the network. Each cell in a Vitess implementation has a local topology service, which is hosted in that cell0 码力 | 210 页 | 846.79 KB | 1 年前3
The Vitess 5.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically availability zone. Vitess gracefully handles cell-level failures, such as when a cell is cut off the network. Each cell in a Vitess implementation has a local topology service, which is hosted in that cell0 码力 | 206 页 | 875.06 KB | 1 年前3
The Vitess 8.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically availability zone. Vitess gracefully handles cell-level failures, such as when a cell is cut off the network. Each cell in a Vitess implementation has a local topology service, which is hosted in that cell0 码力 | 331 页 | 1.35 MB | 1 年前3
The Vitess 7.0 Documentation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84 5 Network Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data center, availability zone or group of computing resources A cell is a group of servers and network infrastructure collocated in an area, and isolated from failures in other cells. It is typically availability zone. Vitess gracefully handles cell-level failures, such as when a cell is cut off the network. Each cell in a Vitess implementation has a local topology service, which is hosted in that cell0 码力 | 254 页 | 949.63 KB | 1 年前3
Pentest-Report Vitess 02.2019investigated for common problems like AllowPrivilegeEscalation, the application of name-space rules in the network policies, the running of pods in privileged mode, and the characteristics of the DefaultServiceAccounts fragment does have an effect, it was found to be impossible to break out of the base directory. • The network communication between the different Kubernetes application pods was analyzed in order to find potential0 码力 | 9 页 | 155.02 KB | 1 年前3
共 10 条
- 1













