3 ms·
Just a guess, but those people probably updated their installation with an existing (insecure-by-default) configuration in place. Very little software like this
by exogen 10y ago
Just a guess, but those people probably updated their installation with an existing (insecure-by-default) configuration in place. Very little software like this will mess with an existing configuration, so that upgrading doesn't appear to break anything. That's how they'd be on a secure-by-default version but still be insecure.
- achillean 10y agoYeah, I could definitely see that happening though the overall number of exposed MongoDBs has also increased. And there are Docker images that come w/ insecure defaults ala: https://hub.docker.com/r/swcc/docker-mongodb/~/dockerfile/ https://hub.docker.com/r/swcc/docker-mongodb/~/dockerfile/ One of my concerns is that people are piling onto MongoDB because "it's web scale" and ignoring potentially systemic security issues that aren't specific to MongoDB. The same issue exists for Riak, Cassandra, Memcache etc.: https://blog.shodan.io/memory-as-a-service/ https://blog.shodan.io/memory-as-a-service/