Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. The Insider News
  4. Major security alert as 40,000 MongoDB databases left unsecured on the internet

Major security alert as 40,000 MongoDB databases left unsecured on the internet

Scheduled Pinned Locked Moved The Insider News
mongodbdatabasecomsecuritysales
10 Posts 9 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    Kent Sharkey
    wrote on last edited by
    #1

    Information Age[^]:

    Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

    NoSQL? More like NoSecurity, amirite folks?

    I'll get my coat.

    H G Kornfeld Eliyahu PeterK N D 6 Replies Last reply
    0
    • K Kent Sharkey

      Information Age[^]:

      Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

      NoSQL? More like NoSecurity, amirite folks?

      I'll get my coat.

      H Offline
      H Offline
      harsimranb
      wrote on last edited by
      #2

      Geez...Wouldn't that be common sense for any db admin??!!

      H.B.

      1 Reply Last reply
      0
      • K Kent Sharkey

        Information Age[^]:

        Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

        NoSQL? More like NoSecurity, amirite folks?

        I'll get my coat.

        G Offline
        G Offline
        Gautham Prabhu K
        wrote on last edited by
        #3

        OMG!!! I think common sense is not so common any more..

        1 Reply Last reply
        0
        • K Kent Sharkey

          Information Age[^]:

          Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

          NoSQL? More like NoSecurity, amirite folks?

          I'll get my coat.

          Kornfeld Eliyahu PeterK Offline
          Kornfeld Eliyahu PeterK Offline
          Kornfeld Eliyahu Peter
          wrote on last edited by
          #4

          I can't see how that's the fault of MongoDB - all you need is fire some DB admins around the word...

          Skipper: We'll fix it. Alex: Fix it? How you gonna fix this? Skipper: Grit, spit and a whole lotta duct tape.

          "It never ceases to amaze me that a spacecraft launched in 1977 can be fixed remotely from Earth." ― Brian Cox

          J 1 Reply Last reply
          0
          • Kornfeld Eliyahu PeterK Kornfeld Eliyahu Peter

            I can't see how that's the fault of MongoDB - all you need is fire some DB admins around the word...

            Skipper: We'll fix it. Alex: Fix it? How you gonna fix this? Skipper: Grit, spit and a whole lotta duct tape.

            J Offline
            J Offline
            Jorgen Andersson
            wrote on last edited by
            #5

            If they're using Mongo they probably already fired all DB Admins. And that's the root of the problem.

            Wrong is evil and must be defeated. - Jeff Ello

            1 Reply Last reply
            0
            • K Kent Sharkey

              Information Age[^]:

              Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

              NoSQL? More like NoSecurity, amirite folks?

              I'll get my coat.

              N Offline
              N Offline
              Nagy Vilmos
              wrote on last edited by
              #6

              I remember back in the dark ages a similar story about how many Oracle systems still had scott/tiger enabled with admin rights. It is the same thing with MongoDb, I like Mongo and I use it, but if you are such a numpty as to put your DB on da webs and not tie down access to it then you deserve every piece of data that gets stolen.

              veni bibi saltavi

              R 1 Reply Last reply
              0
              • K Kent Sharkey

                Information Age[^]:

                Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

                NoSQL? More like NoSecurity, amirite folks?

                I'll get my coat.

                D Offline
                D Offline
                Duncan Edwards Jones
                wrote on last edited by
                #7

                Quote:

                telecoms database with 8 million customer phone numbers and addresses

                I remember when that sort of highly secret information was only available in book form...and was left on your doorstep.

                J 1 Reply Last reply
                0
                • D Duncan Edwards Jones

                  Quote:

                  telecoms database with 8 million customer phone numbers and addresses

                  I remember when that sort of highly secret information was only available in book form...and was left on your doorstep.

                  J Offline
                  J Offline
                  Jorgen Andersson
                  wrote on last edited by
                  #8

                  Hilarious!

                  Wrong is evil and must be defeated. - Jeff Ello

                  1 Reply Last reply
                  0
                  • K Kent Sharkey

                    Information Age[^]:

                    Students discover overwhelming number of MongoDBs without access control, including a French telecoms database with 8 million customer phone numbers and addresses

                    NoSQL? More like NoSecurity, amirite folks?

                    I'll get my coat.

                    J Offline
                    J Offline
                    JMK NI
                    wrote on last edited by
                    #9

                    There's an awesome Defcon talk on this called Massscanning the Internet[^]. Basically if you know the port a particular service runs on, you can use a tool called MasScan[^] to scan the entire internet for it in ten minutes (if your internet is fast enough). Then write a script to loop through each result and try and login with default credentials and bam! Security Alert!

                    1 Reply Last reply
                    0
                    • N Nagy Vilmos

                      I remember back in the dark ages a similar story about how many Oracle systems still had scott/tiger enabled with admin rights. It is the same thing with MongoDb, I like Mongo and I use it, but if you are such a numpty as to put your DB on da webs and not tie down access to it then you deserve every piece of data that gets stolen.

                      veni bibi saltavi

                      R Offline
                      R Offline
                      Rob Grainger
                      wrote on last edited by
                      #10

                      Sadly though, it is our data which is likely to be stolen.

                      "If you don't fail at least 90 percent of the time, you're not aiming high enough." Alan Kay.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups