Incident 01 · open
The client chose the request host
nginx did not overwrite X-Forwarded-Host and the app read the host from it. A storefront request with a forged header got the admin sign-in form.
Servers and security
It has to stay alive, fast and closed. That part is entirely ours: from firewall rules to the sandbox of every service.
0
product services running as root
1.3
systemd-analyze score, out of 10
12
threat classes for every module
1
command to deploy with rollback
Incident 01 · open
nginx did not overwrite X-Forwarded-Host and the app read the host from it. A storefront request with a forged header got the admin sign-in form.
Incident 02 · open
The emailed link gave an admin a session without the gate or second factor. Access to the admin mailbox bypassed both layers.
Incident 03 · open
Monitoring showed 8 GB free out of 116. The tournament server was recording a demo around the clock.
Incident 04 · open
Parsing large demos ate memory, and the OOM killer took neighbouring processes along with the site.