How To Prevent Redis Headcrab Attack For Multi Node Deployment?

Redis server detection RPA servers- HeadCrab attack uses novel Redis malware.

Overview:

Headcrab attacks target unsecured open-source Redis databases. These attacks do not affect Redis Enterprise, which includes built-in high-availability (HAA) features. This guide outlines steps to secure open-source Redis deployments and move Orchestrator to a single node temporarily during the implementation to avoid downtime.


Resolution:
To secure open-source Redis against Headcrab attacks, Redis has released five basic steps. Find detailed instructions on implementing these steps in documentation 5 Basic Steps to Secure Redis Deployments.

To perform the necessary security actions, move the Orchestrator to a single node by disabling Redis in the uipath.orchestrator.dll.config and the appsettings.Production.json file within the identity folder. This will help avoid downtime during the security enhancement process.