The overall neglect of some security features in the creation of Redis Database Servers came back to haunt the project years later, as Risk Based Security (RBS) reports that it discovered 6,338 Redis servers that had been compromised.
Redis is a NoSQL database server that is ideal for storing data in a key-value format, using an in-memory system for data processing and subsequent queries. According to statistics from DB-Engines, Redis ranked tenth in terms of usage and popularity in 2015.
Because Redis was built with performance in mind, in a default setup, the database does not have any kind of authentication or other strong security features.
This means that anyone can access its contents just by knowing the IP and port. Worst of all, towards the end of 2015, an exploit appeared that allowed a third party to store an SSH key in the authorized_keys file from any other Redis server that did not have an authentication system in place.
There are over 30,000 unauthenticated Redis database servers available online. According to RBS researchers, 6,338 of these servers were compromised.
The company came to this conclusion after performing a non-intrusive scan using Shodan. RBS researchers’ interest peaked when they analyzed a hacked server featuring the “crackit” SSH key, which was associated with an email address [ryan@exploit.im] that they had previously encountered in other incidents.
Scanning with Shodan for open Redis servers that were not characterized by non-standard SSH keys, the researchers found 5,892 instances of SSH keys associated with the ryan@exploit.im email address. In addition, they found 385 keys associated with root@chickenmelone.chicken.com and 211 keys associated with root@dedi10243.hostsailor.com.
The most common non-standard keys were “crackit”, “crackit_key”, “qwe”, “ck” and “crack”. In total, RBS found 14 unique emails and 40 unique SSH key. As RBS explained, these reports appear to be the work of multiple groups or individuals.
As for the exposed Redis database versions, the researchers found 106 different versions, ranging from the newest 1.2.0 version to the most recent version, 3.2.1.
"While we haven't been able to find anyone to confirm this publicly, it seems from our analysis that we have confirmed two things: the first is that this is not something new and the second, that some servers are out there infected and not being used for anything malicious," the RBS researchers explained.
The security firm recommends that webmasters update their Redis databases to the latest version and enable “protected mode,” a security feature introduced in Redis with version 3.2.
These 6,338 servers are still exposed to this day, meaning new threat actors could easily put them at risk again.

