13 ms·
Online databases dropping like flies, with 10,000 falling to ransomware
- tkyjonathan 10y agoAbsolutely ridiculous that MongoDB is this insecure by default.
- peterwwillis 10y agoYou expected a database sitting on the public internet to be secure? A very young one, no less? Who is downvoting this? People who hate common sense?
- abiox 10y agoi can't downvote, but your question seemed like a nonsequitur.
- jasondc 10y ago+1 Ideally, databases should never have internet access
- monksy 10y agoTell that to frontend javascript devs who think they don't need a back end system. Without a public facing DB they're pretty much dead in the water.
- bartread 10y agoThe more things change, the more they stay the same. I'm thinking of people who back in the 90s/early noughties didn't want to bother with a middle tier application, and instead talk directly to the database from their fat clients(1) because it was easier. (1) This, btw, is what many SPA are: fat client apps running within a browser. When I came back to web development four years ago one of the biggest surprises was how much like desktop development it had become in many ways.
- cm2187 10y agoIf you are using one of the main cloud provider, the database they provide will almost always do. For azure at least, they protect it with a firewall that block all IPs by default. But a database with no internet access is unrealistic.
- ivanhoe 10y agoHow about expecting that DB doesn't bind to 0.0.0.0 by default and to force passwords to be set during the installation? Is that such an unreasonable thing to expect?
- peterwwillis 10y agoYes. Expecting anything to be secure by default is unreasonable. It would be nice, but I would not just expect it, I would confirm it. Expecting it to be secure on the internet is even less reasonable.
- ivanhoe 10y agoI'm not talking about it being "secure by default". Just not being obviously insecure by default is more than enough...
- raverbashing 10y ago"Recent" versions aren't. If you install .rpm/.deb versions you're also covered (And anyone who deploys any service on an internet-facing server should know what they're doing) See https://blog.shodan.io/its-the-data-stupid/ https://blog.shodan.io/its-the-data-stupid/
- jlgaddis 10y ago> (And anyone who deploys any service on an internet-facing server should know what they're doing) I agree that they should. History has shown us, however, that they very often don't.
- Cozumel 10y agoIf people RTFM it would never have been an issue.
- threeseed 10y agoThis is Hacker News not Fox News. At least be intellectually honest. It's not insecure by default. It just binds to all interfaces. Apache and Nginx both do this and we don't consider them to be insecure. Should a database be doing this ? That's debatable since it's a tradeoff between security and ease of use. But that said if you are running an internet facing server without a firewall then you will have bigger problems than just your database.
- e12e 10y agoI've always thought that the biggest service openbsd did, was teach people to remove unneeded stuff and turn off unused services. Remember when people used to sneer that X years without remote root in the default install was no wonder, because the Base install didn't do anything useful? I also don't get this "firewall" idea. Why make something listen for everything, and then place a system outside to restrict it? Why not just whitelist what you want to listen to in the first place? Note, I get that binding an application to localhost and then letting a dedicated proxy do the heavy lifting to link up with other systems (eg stunnel or haproxy) - but what does packet level filtering really gain you? In general I see firewalls as just adding complexity - one more source of bugs and potential mis-configuration. (Say the fun when ipv6 exposes the soft inner network that everyone thought was "firewalled" when in fact it just had broken connectivity due to chappy NAT borne from scarcity of routable addresses).
- vacri 10y agoIf you don't necessarily know what's going to be running on a machine, a firewall gives you control over what's allowed in or out. If a lazy dev installs some tool that listens to everything on a machine that's on the internet, a firewall will protect you from their laziness. In an ideal world, everyone would care about this stuff (and have time to properly set these things), but we're not in an ideal world.
- e12e 10y agoRight. I would rather fix the broken developer once, than paper over systems with a firewall. Perhaps I'm too idealistic. (IMHO proper devops does this - helps give devs a proper view of system administration by sharing knowledge and responsibilities). I'm also pessimistic enough that I think allowing development to install back doors (eh, "useful helper daemons") willy-nilly in production systems is a bad idea ;-)
- liveoneggs 10y agoinsecure defaults are a key driver for increased adoption! It's worked for, at least: mongodb, redis, jboss, and elasticsearch
- Will_Do 10y agoI feel like this is a new golden age in being a blackhat. Back 5-10 years ago there was no IOT and all databases were password protected by default. Now we have: 1. IoT with basically no security 2. No(Auth)SQL. Also, dev time has become so expensive, the InfoSec teams in the companies I've worked at have had shockingly low head counts for all the responsibilities they have.
- bostand 10y ago3. Bitcoin
- 21 10y agoIndeed, bitcoin is the true enabler. But the dangers are pretty high. You never know how ten years from now the digital trail you left comes back to bite you. Cashing large amounts it's not trivial. Sure, you can meet in private locations with local bitcoin buyers, but when you have $1 mil to sell it gets tricky, there aren't that many buyers in any particular area. And then you have the problem of justifying how you suddenly have one million.
- branchless 10y agoWhat actually happens when you try to get out of bitcoin? Let's say I put in $5k a few years back which is now worth $100k. I have to go on the exchange and nominate a bank account then sell then they transfer say USD into my account? At this point is this "capital gains" taxable? Assuming I'm willing to pay the tax if it's due has anyone had trouble with authorities questioning your new cash pile say if before this you had no real money and lucked out on Bitcoin?
- olegkikin 10y agoThe government doesn't give a shit, as long as it's legal and as long as you pay the taxes. Bitcoin isn't the only thing in the world that goes up and down in value, so it isn't new from the tax perspective.
- tzmudzin 10y agoThe interesting part is the relatively low ransom amount. I understand it needs to be low enough to make payment an "attractive" option (at least compared to other means of recovery, if any...). But 200 USD is significantly less than the 500 USD ransom extorted from private PC users. Should we conclude the extortionists expect the database content to be worth less to a company owning it than a private person is willing to pay for his/her pictures, music files and documents?
- kukx 10y ago"Promises to restore the databases in return for a ransom payment are dubious, since there's no evidence the attackers copied the data before deleting it." I guess the high risk of getting nothing in return is affecting the pricing.
- matt4077 10y agoThey should do a tit-for-tat data release. Pay 1/10 of the ransom, get 1/10 of the data.
- 21 10y agoIf the data is valuable presumably it would have a backup. Many of these could be caches, or rebuildable from other sources. Many could be disposable. Since you can't really know which database is valuable and which not, you sort of average the price, since this is volume game. Or maybe he want's to give the impression that this is not very profitable, to keep others from doing the same.
- g00gler 10y agoI assume that's the case. Securing mongodb isn't rocket science, it's not all that different from any other database, so I can't imagine a business with any value has unsecured mongodb instances. What I mean is, it's pretty ignorant that just because authentication isn't on by default you don't turn it on at all. Even if you don't want to or don't think to configure mongodb itself setting up a firewall also seems to be common sense. Thus, the only reason they'd be unsecured is they're either for random tests or hobby.
- kennysmoothx 10y agoDoes anyone know of a "security checklist" one could follow for mongodb? I have not used mongodb in any production environment but it would be nice to know what one should do to make it secure.
- cpolis 10y agohttps://docs.mongodb.com/manual/security/ https://docs.mongodb.com/manual/security/ is a good start(not being glib).
- kennysmoothx 10y agoAwesome! Thanks for the heads up https://docs.mongodb.com/manual/administration/security-checklist/ https://docs.mongodb.com/manual/administration/security-chec...
- jlgaddis 10y agoI don't use MongoDB but other, generic recommendations apply and would likely go a long way towards preventing this: - deny (all) incoming traffic by default - permit only desired traffic (to specific ports) from specific hosts - avoid binding (listening) to interfaces you don't need to - set up / verify authentication is in place In addition to the link to the security manual that cpolis posted, there's also a MongoDB Security Checklist [0]. [0]: https://docs.mongodb.com/manual/administration/security-checklist/ https://docs.mongodb.com/manual/administration/security-chec...
- kennysmoothx 10y agoThanks! I appreciate your recommendations!
- elchief 10y agoStep 1: Uninstall mongo
- threeseed 10y ago
- iask 10y agoA couple of things: Person develops 2 or 3 apps, setup 2 or 3 databases and thinks he/she is a professional. Many businesses and managers care less about security and more about getting the deliverables into production. Many CEOs and managers lack the understanding that once you launch (app, store, website etc) it doesn't end there, instead, moves into maintenance. My company just hired an external company to assist with our IT infrastructure. I was asked to meet with the person that showed up to begin the take over. He was not interested at all in understanding what we do as a business. If you don't understand your clients, their interests, their responsibilities and obligations then, simply put, they are fucked!
- synicalx 10y agoI see this sort of nonsense ALL THE TIME. Most of the work I do/have done is at non-tech companies, so no one above the 'team leader' level is even remotely technical. Any sort of security that costs time or money becomes either a joke ("You want us to spend money on what?!"), or is just ignored entirely. In my experience the issue isn't so much that C's and managers lack understanding, it's that they refuse to acknowledge that they lack understanding and refuse to listen to people who do understand because it's "Just IT". This mindset is something I've seen backfire many times over the years, and in the end it always ends up costing more than just doing things properly in the first place. /endrant
- kazinator 10y agoNo excuse for not backing up an online db at least daily. An irrecoverable disk crash could hold your db ransom for $Inf.
- sakabaro 10y ago> People who administer websites that use MongoDB should ensure they're avoiding common pitfalls by, among other things, blocking access to port 27017 or binding local IP addresses to limit access to servers. Misconfigured mongodb servers are the issue here, not firewall. Default mongodb shouldn't listen blindly to any connections though.
- kahnpro 10y agoI know a company that got hit by this. Through some mistake in configuration, they exposed their mongodb. What I understand is that the ransom request is a total scam, they didn't download or encrypt any data, just ran the drop command and inserted the ransom message. But they didn't hit the oplog/journal, fortunately the full history (a few months of data) was still in the journal, so they were able to replay it (minus the drop commands) and restored their data. Certainly scared a lot of people and (hopefully) taught a lesson about double-checking what's exposed to the internet.
- spullara 10y agoBlackhat hackers attained product-market fit in 2015.
- cm2187 10y agoI am not familiar with MangoDB but if 10,000 MangoDB are "misconfigured" then perhaps the defaults are to blame, not the users.
- tracker1 10y agoI think there is definitely a need for some work in this space.. but the fact is, there are a LOT of databases open to the wild. These are just the ones that didn't bother to set an admin password. They also didn't setup any firewall rules. 0. upload client public key 1. Setup SSH auth by cert/key 2. Move SSH to non-standard port 3. Enable passwordless sudo 4. Disable password auth 5. Setup firewall to only allow the new ssh port 6. Setup port knocking Those are the first few things I do on a server... As locked down as I can get before doing anything else... of course, I'll also put the new ssh port and an alias in my ~/.ssh/config ... Most cloud providers offer the option to have a "private" IP space... just having a proper firewall ufw/ipchains/iptables, etc config can go a long way towards helping lock things down. Of course, that only goes so far when you aren't using passwords or TLS for client/server communications. But it's better than leaving the front door open with a sign saying as much.
- andybak 10y agoSeveral people below mention the ransomware aspect of this is a scam and no data is ever returned. This is ironically a good thing as it poisons the well for 'legitimate' ransomware. The less people expect paying up to restore their data, the less people will pay up and the less viable ransomware is as a business model.