Exposed MCP servers across the internet
knostic.ai
Exposed MCP servers across the internet
1–10 of 31 posts
Re: Exposed MCP servers across the internet
#2As is the article feels a bit light on details. I'm not surprised that there are open servers out there, but if you're writing an article about that, at least provide interesting details.
Re: Exposed MCP servers across the internet
#3Re: Exposed MCP servers across the internet
#4Re: Exposed MCP servers across the internet
#5Here we go again.
Before we had seen (and there still) MongoDB databases exposed all over the internet with zero credentials protecting them. (you can just connect to them and you are in.)
Now we have exposed MCP servers waiting to be prompt injected and their data to be exfiltrated from say, a connected service or database if they are connected to any. [0]
So now you can just talk to anyone's exposed MCP server and ask for the secret passwords, environment variables and sensitive data.
And the AI will just hand it all over.
Re: Exposed MCP servers across the internet
#6> We identified a total of 1,862 MCP servers exposed to the internet. From this set, we manually verified a sample of 119. All 119 servers granted access to internal tool listings without authentication. Here we go again. Before we had seen (and there still) MongoDB databases exposed all over the internet with zero credentials protecting them. (you can just connect to them and you are in.) Now we have exposed MCP ser…
Re: Exposed MCP servers across the internet
#7> We identified a total of 1,862 MCP servers exposed to the internet. From this set, we manually verified a sample of 119. All 119 servers granted access to internal tool listings without authentication. Here we go again. Before we had seen (and there still) MongoDB databases exposed all over the internet with zero credentials protecting them. (you can just connect to them and you are in.) Now we have exposed MCP ser…
safety people are excessive, too
Re: Exposed MCP servers across the internet
#8What happened to best practices? Starting a demo locally is something but opening it up to the internet irresponsibly is something else.
Re: Exposed MCP servers across the internet
#9Hmmm. I thought that's the idea of MCP server - give LLM an interface to use your service. Why would it require authentication? One of the tools could be to authenticate. Please destroy this position if I'm wrong.
The article would actually be interesting if they tried either of those with the servers they found.
Re: Exposed MCP servers across the internet
#10Hmmm. I thought that's the idea of MCP server - give LLM an interface to use your service. Why would it require authentication? One of the tools could be to authenticate. Please destroy this position if I'm wrong.