|
|
|
|
|
by dpina
3835 days ago
|
|
> Update 2: Earlier this afternoon, Chris Vickery confirmed that the three IP addresses that were disclosing user information have been secured. The issue wasn't a hack, but a misconfigured MongoDB installation. > The source of the configuration error isn't clear, as neither the ISP nor Sanrio has answered questions on the matter. A MongoDB database open to the outside world on a public IP address? |
|
Maybe someone was inspired by this article?
https://blog.shodan.io/its-still-the-data-stupid/
> At the moment, there are at least 35,000 publicly available, unauthenticated instances of MongoDB running on the Internet. [...] all of the exposed databases combined account for 684.8 TB of data.