Live data from Hacker News

Finding MongoDB instances without any authentication

blog.shodan.io

41–44 of 44 posts

Re: Finding MongoDB instances without any authentication

#41
post #27

Earlier quoted context omitted.

Maybe, but running unauthenticated databases on the public internet is negligent at best.

No. It could be simple ignorance. Or an accident. In your world, what is it at worst? Criminal? Capital?

Of course it depends on the context. I don't know if it's reasonable to expect a small family clinic, therapist, or dental office to secure their client information. It seems that people just mass scan the internet looking for already known vulnerabilities.

However, if it's a mid-sized business handling important information, like payment information, then I do think there ought to be a standard of dutiful behavior, because otherwise who pays for the externalities?

Re: Finding MongoDB instances without any authentication

#42

Can't malware/bots use these databases for communication?

Hehe, for that matter it'd make a hell of a means of distribution for illicit materials (pirate software/movies)... Think db nodes to find/query for torrents...

Open ftp uploads all over again...

Re: Finding MongoDB instances without any authentication

#43
post #21
post #4

Earlier quoted context omitted.

They're entirely responsible for the damage that was inflicted. Attempting to shift the blame to you is childish at best.

This is a victim-blaming myth. The prime responsibility for the damage is the person who did the damage. Not the discloser, and not the victim.

[deleted]

Re: Finding MongoDB instances without any authentication

#44
post #27

Earlier quoted context omitted.

Maybe, but running unauthenticated databases on the public internet is negligent at best.

No. It could be simple ignorance. Or an accident. In your world, what is it at worst? Criminal? Capital?

It could also be leftover testing systems that haven't been torn down yet, with nothing interesting in them. The internet is full of them.
Post reply on HN