Vulnerability Assessment of Default Configuration in Redis
| dc.contributor.author | Phyo A. | |
| dc.contributor.author | Rassameeroj I. | |
| dc.contributor.correspondence | Phyo A. | |
| dc.contributor.other | Mahidol University | |
| dc.date.accessioned | 2026-05-28T18:35:31Z | |
| dc.date.available | 2026-05-28T18:35:31Z | |
| dc.date.issued | 2026-05-08 | |
| dc.description.abstract | Redis, a widely used in-memory key–value database, powers caching, session handling, and analytics in modern web applications. Its default configuration prioritizes performance but neglects security, leaving deployments vulnerable to missing authentication, unencrypted communication, weak memory persistence limits, and exposed high-risk commands. We present a dual-mode Python scanner that unifies direct Redis probing with web-layer–mediated testing via Server-Side Request Forgery (SSRF) and Server-Side Command Injection (SSJI) to reveal misconfigurations even when Redis is not directly exposed. The design contributes a structured workflow that seamlessly switches between direct and indirect paths, a non-destructive commandexposure heuristic that infers whether dangerous commands are available or renamed and disabled using error-signature analysis and an extensible module set covering authentication, TLS, memory, persistence, and module loading with severity-ranked reporting. In a containerized testbed with TLS and non-TLS instances and a vulnerable PHP front end, the scanner detected seeded misconfigurations across seven categories with no false positives. The average per-module runtime was less than 6 seconds with mean CPU utilization below 1.2% and memory usage 0.36 – 0.42%. These results indicate that the approach is accurate, lightweight, and practical for security audit workflows. | |
| dc.identifier.citation | Icsim 2026 Proceedings of 2026 the 9th International Conference on Software Engineering and Information Management (2026) , 72-76 | |
| dc.identifier.doi | 10.1145/3796315.3796326 | |
| dc.identifier.scopus | 2-s2.0-105039486914 | |
| dc.identifier.uri | https://repository.li.mahidol.ac.th/handle/123456789/116961 | |
| dc.rights.holder | SCOPUS | |
| dc.subject | Computer Science | |
| dc.title | Vulnerability Assessment of Default Configuration in Redis | |
| dc.type | Conference Paper | |
| mu.datasource.scopus | https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105039486914&origin=inward | |
| oaire.citation.endPage | 76 | |
| oaire.citation.startPage | 72 | |
| oaire.citation.title | Icsim 2026 Proceedings of 2026 the 9th International Conference on Software Engineering and Information Management | |
| oairecerif.author.affiliation | Mahidol University |
