40,000 Exposed MongoDB Databases Discovered Online

Significant Vulnerability Exposed in MongoDB Databases

Recent investigations have revealed that nearly 40,000 organizations utilizing MongoDB, a popular NoSQL database known for its performance and flexibility, are currently unprotected and susceptible to cyber attackers. This alarming information was brought to light by researchers from the University of Saarland in Germany, specifically the Centre for IT Security, comprising students Kai Greshake, Eric Petryka, and Jens Heyens. The researchers discovered that numerous MongoDB databases running on TCP port 27017 are accessible online without sufficient security measures.

MongoDB serves a diverse array of companies and applications, exhibiting its capability for scalability and high availability. Companies rely on MongoDB for its in-memory computing capabilities, which facilitate efficient data handling. However, this widespread adoption has also revealed a troubling trend regarding database exposure, as evidenced by the researchers’ findings.

The conducted analyses revealed that the researchers could easily obtain “read and write access” to these unsecured MongoDB databases without needing advanced hacking techniques. Among the databases, they identified one associated with a French telecommunications company, which contained sensitive information regarding 8 million customers, including names, addresses, and phone numbers.

The implications of this vulnerability are severe. The Saarland university statement highlighted the gravity of the situation, noting that unauthorized users could retrieve and modify significant amounts of personal customer data, including potentially sensitive financial information.

Attackers can exploit this vulnerability quite readily. A straightforward port scan for TCP port 27017 can uncover these exposed databases within a few hours, particularly using rapid scanning tools such as “masscan.” Additionally, the Shodan search engine further facilitates these attacks, providing hackers with detailed access to IP addresses hosting these unprotected MongoDB databases.

In response to these findings, the researchers promptly alerted MongoDB, the French Data Protection Authority (CNIL), and the Federal Office for Information Security in hopes of notifying database owners about the discovered vulnerabilities. MongoDB has since acknowledged the issue, emphasizing their commitment to security. The company advised affected entities to utilize the latest installation procedure, which automatically restricts network access to localhost and to consult the MongoDB Security Manual for further safeguards.

From a cybersecurity perspective, this incident may involve several MITRE ATT&CK tactics, particularly initial access through exploitation of vulnerabilities and insufficient configuration management. The ease with which these databases can be accessed indicates a clear lack of security measures, making them prime targets for cybercriminal activity.

This situation serves as a stark reminder for business owners about the importance of maintaining adequate cybersecurity protocols. Organizations leveraging MongoDB must ensure that their databases are appropriately secured, lest they fall victim to the plethora of threats faced in today’s cybersecurity landscape.

Source link