Several thousand MongoDBs without access control on the Internet [pdf]
cispa.saarland
cispa.saarland
This is part of the Slicehost VPS setup guide that PickledOnion wrote back in the day, and it's still one of the first things I do when I get a new box. (Typically right after locking down SSH with a key requirement.)
Edit to add:
http://articles.slicehost.com/2008/4/25/ubuntu-hardy-setup-p... http://articles.slicehost.com/assets/2007/9/4/iptables.txt <-- make sure you change the port 30000 on the SSH to whatever you use on your boxes
[+] You might think "Well, that requires the existence of both a vulnerability in the server and a local privilege escalation exploit", but in practice, you can assume that the attacker has access to both of these. They also probably aren't trying to get into your box, specifically -- your box is merely one of the several thousand Redis instances on the Internet that they're firing e.g. a specially corrupted Unicode string to get a buffer overrun on, at which point they will -- in a mostly automated fashion -- run metasploit (or similar ratware) and turn that into a root shell.
No one else binds to all interfaces by default.
127.0.0.1 localhost
192.168.1.8 localhost
Consequently Postgres was binding to the external IP when it should have been listening on just 127.0.0.1. I only noticed it because I routinely nmap my servers after setting them up. In this case it probably didn't matter, since login would have still required a password, but it's one example of how easily misconfiguration can open holes. Not nearly as bad as Mongo's situation, but a lesson to me to check my work.MongoDB fucks this balance up by recommending you use their package repositories instead of distro maintained packages.
http://memcached.org/downloads
https://www.mongodb.org/downloads
Are identical in having normal binary downloads as the primary installation option.
And you seem to be implying that vendor supplied repositories are somehow unusual. They absolutely aren't.
I don't believe I said that MongoDB recommended their packages over compiling from source.
> And you seem to be implying that vendor supplied repositories are somehow unusual.
Nope.
http://www.heise.de/security/meldung/Studenten-entdecken-Tau...
Original (German language) press release is here: http://www.uni-saarland.de/nc/en/news/article/nr/12173.html
http://seclists.org/fulldisclosure/2014/May/43
Edit: Oh, seems like the site is still up at http://un1c0rn.net/
http://www.mongodb.com/blog/post/mongodb-security-best-pract...
> "The most popular installer for MongoDB (RPM) limits network access to localhost by default."
The first download for Linux at https://www.mongodb.org/downloads is:
> https://fastdl.mongodb.org/linux/mongodb-linux-x86_64-2.6.7....
At the bottom of the page there are alternate links to packages. Here is the description:
> "MongoDB is included in several different package managers. Generally speaking, it is easier to simply install the prebuilt binaries from above."
If the properly packaged versions have secure defaults, maybe you should steer people towards them?
curl $SHODANURL |grep -i class=\"ip\" |cut -d ’/’ -f 3 \ |cut -d ’"’ -f 1|uniq >db.ip
The author at CISPA (in the linked pdf) states to 'paste the html code' however using shodan from the command line, one only has access to 6 verbs that shodan understands. Shodan reveals 34309 mongo databases. I can download their ips but that requires 'query credits' using shodan. How does one use curl here?
iptables -A INPUT -p tcp -s 127.0.0.1 --dport 27017 -j ACCEPT
iptables -A INPUT -p tcp -s 127.0.0.1 --dport 28017 -j ACCEPT
# 2nd: drop from all others
iptables -A INPUT -p tcp --dport 27017 -j DROP
iptables -A INPUT -p tcp --dport 28017 -j DROP
> mongo server.address.or.ip.goes.here
If this connects successfully, that is problematic.
I've found Mongo's authorization setup to be pretty unintuitive, but you can find some information here: http://docs.mongodb.org/manual/core/authorization/ (IIRC, you need to setup the permissions first, then set "auth=true" in mongod.conf and restart the service.)