I'm not clear on why people would be exposing MongoDB on a public address?
This habit of database-like software (does Redis still not offer authentication?) treating authentication/authorization as a second-class citizen is odd.
I guess it has proven to be webscale though [1].