63 ms·
New ‘Meow’ attack has deleted almost 4k unsecured databases
- based2 6y agohttps://arstechnica.com/information-technology/2020/07/more-than-1000-databases-have-been-nuked-by-mystery-meow-attack/ https://arstechnica.com/information-technology/2020/07/more-...
- TA00001 6y agoFor those that want to go deep link diving. 'Meow, I'm a Cat'.
- Pick-A-Hill2019 6y agoOr 'Meow, I'm a Frog'
- petee 6y agoSomehow I feel good about this. The article claims nothing good can come of deleting exposed databases, but I strongly disagree - I'd by far rather my data be deleted than stolen and shared. If the owner doesn't have proper backups AND can't secure a database, they have no business hosting such data, period. IMHO.
- JaggerJo 6y agoagreed.
- menzoic 6y agoCould be both
- glckr 6y agoNo other bad actors can get it, but we don't know if it's already been found, and now that it's gone we have no idea what data is out in the wild. And as you note, we can't trust the companies to accurately report it themselves.
- DyslexicAtheist 6y agomaybe the authors of meow should "improve" it with a feature that reports every instance to HIBP before deleting it. that is if their intention with this malware was a benevolent one :) but I guess feature iteration in malware that is "supposed to be good" would be tricky
- mkagenius 6y ago> reports every instance to HIBP no, that doesn't make sense if its only meow who found it. And since there is no way to know that, it does not make sense to mail a copy to hibp
- petee 6y agoI think you make an important point though - deleted or not, there is no real way to know what's been exposed, and no guarantee that they'll ever admit it; so torch all the data expeditiously, and we'll just have to comb through 'successful' leaks just as always. Another side is that with their database blanked, that will force more companies to explain their downtime or complete loss of data, rather than quietly secure it again and pretend nothing happened
- Alex3917 6y agoIdeally they'd report it so that password managers could warn everyone, but with just the database URI there isn't necessarily any obvious way to know what domain or business its associated with.
- wtracy 6y agoIf the attacker can write to the DB, then they can add entries to every table with the string "Hey your database is unsecured!"
- GekkePrutser 6y agoDoesn't really matter, as long as the credential is exposed, users can be warned. No matter where it came from.
- neutronman 6y ago+1 Any entity this irresponsible shouldn’t hold data.
- bhargav 6y agoThis also affected people who use software for things other than businesses. People with IoT apps for their home, researchers, etc. Our field is vast and there is a large variance in people just using the basics of CS and those who keep up with standards and best practices, etc. Your statement is basically akin to someone saying that it’s fine for people to get robbed if they went out with their wallet; or worse.. killed.
- nend 6y ago>Your statement is basically akin to someone saying that it’s fine for people to get robbed if they went out with their wallet; or worse.. killed. Uhh no? The analogy would be that there's some benefit that comes from someone's wallet being destroyed, instead of stolen.
- unstatusthequo 6y agoI’d say it’s closer to leaving your wallet on the street. If you don’t care to protect it you should assume someone will fuck with it.
- hobs 6y agoJust because its offering some useful service doesn't indemnify the ownership from the bad methods they use to deliver the service. Exposing your database to the internet with default creds is not "standards and best practices" - its highly negligent, and if you are taking people's money for such a service, I have no pity for you.
- hddherman 6y agoThat's not a good argument, inexperience does not excuse exposing user data.
- petee 6y agoIf you can't or don't know how to secure it, it shouldn't be online. My argument is more akin to a child learning not to leave their bike unattended on a city street corner overnight. I can come by pick up the bike, and tell you the dangers, but there's only one real way to learn. And clearly my opinion isn't even close to comparison with somebody being killed in a robbery.
- derefr 6y agoI'm ambivalent about this action in most cases, but in some specific cases there can be a clear reason to have an exposed database: namely when the database is a guest-accessible, read-only repository of public data, i.e. the self-hosted equivalent of publishing a Google BigQuery dataset. As someone who runs such a "public-access data library" myself, I would be slightly annoyed if someone came along and burned it down, just because it has an unpatched vulnerability. ...but if it got deleted because I left default admin creds on it, though, that'd be my own fault.
- jmvoodoo 6y agoDatabases that are read only would be unaffected by this attack.
- derefr 6y agoRead-only in practice, not inherently read-only in the way that e.g. CD-ROM is. Such systems still need to have their otherwise-static dataset updated "online" by an ETL pipeline agent-user. Which often means, in the DBMSes with less fine-grained security models, that such users need to have full DML (and even DDL) capabilities, rather than only insert capability.
- dtech 6y agoThis attack was only possible on databases with unsecured or weakly secured read-write access.
- asdfasgasdgasdg 6y agoI think this is a little simplistic. Depending on what data is being deleted, it may have real life economic consequences for individual people. What if one of the databases has a record of credits you've purchased at your local spin studio? Hopefully they have a back up, but if they don't, you and/or the owners stand to make significant losses. Are there databases that could be lost without consequence except to their owner? Sure. But that is far from all of them. I also just think it is a little uncharitable to wish harm on people simply because whoever did their IT was inexpert at their job? Like, how does the local mom and pop correctly evaluate a person's IT chops? The nephew says they can set up their website for cheap, and they want to be nice, so they give him the job. Turns out he's a newb and later their database gets deleted and you are on here saying that's a good thing? Hrm. I don't agree.
- Drakim 6y agoIt can definitely have real world consequences, but couldn't the same be said for somebody being a whistleblower for a company that doesn't following building codes? The company could take a huge financial hit and people might lose their jobs because of their practices being exposed.
- asdfasgasdgasdg 6y agoSometimes the best path forward does harm, sure. It's just hard for me to agree that deleting these databases is the harm-minimizing path. One example of a less harmful path that comes to mind immediately is installing a random password on the unsecured database and emailing the domain owner the password. That would cause downtime but it would limit the irreversible damage. You could even say that you will delete the database if it is found again with an unsecured password, if you wanted to add some stick to your carrot. It does not seem like this attack has harm-minimization in mind.
- deleted 6y ago[deleted]
- pojzon 6y ago
- gwright 6y agoWould you feel the same way if someone burned your house down if you left the door unlocked? Would you support the idea of people walking through a neighborhood and checking every door in a similar way? Does your opinion change if it happened in a business district? I think it is fine to argue that doors should be locked but that doesn't mean that a crime hasn't been committed when someone takes advantage of a situation.
- cm2187 6y agoI don't think the parent suggests it exonerates the hackers. Just that the clients are better off.
- gwright 6y agoBetter off? The idea that victims deserve to be victimized because they didn't take enough care is trotted out every time a security issue comes up on HN.
- wolco 6y agoThr victims are the unaware customers who's data has been stolen because the company wasn't providing security. If a business left the store open with the customers credit cards details on display. Anyone passing by can go in and copy that info. Someone sees this and burns the exposed records. Perhaps they helped the victim. Remember no one burned the store down or the table holding the records. They burned only the exposed records.
- goatinaboat 6y agoSomehow I feel good about this. Frankly anyone who is still using MongoDB is professionally negligent and this was if not deserved then certainly inevitable.
- koonsolo 6y agoWho says it's consumer data? It can be a personal project, a blog, etc. Just because it's not secure doesn't mean you should delete the data, because where does such reasoning end? Reminds me of the super meat boy web version with database creds in client. Dev knew, but just did a quick implementation. Hacker wanted to prove his point and ruined it for everybody. Making a secure version was not worth the effort, so now because of this prick nobody could enjoy it.
- klyrs 6y ago> Somehow I feel good about this. For me, it's not exactly "good." But I am more upset with the database owners than I am with the kitties. Don't leave the barn door open, or this (or worse) will happen to you, and happen again. If they were instead exfiltrating and selling the data, the equation would change. I'm not saying the cats are doing good, but I do say that the "responsible adults" did the greatest harm by not cat-proofing their databases that contain PII.
- richardrk2 6y agoI wholeheartedly agree. I cannot think of a scenario where a company exposes my data and I would not want it to be deleted ASAP. The only thing is that such companies might not be able anymore (if data was not backed up) to email me about a “breach”.
- zbuf 6y agoI don't have a feeling one way or the other, but I see where you're coming from and I think there's an interesting aspect that many of the folks here seem to be missing. Were this sort of attack to become part of the "noise" of the internet (much as the continual bombarding of my SSH ports) then peoples databases would get deleted _before_ they contain any meaningful amount of data. So in practice this sort of gross vandalism is limited to the appearance of such an attack, but not ongoing. I had this the other day building OS images, which accidentally left the system a passwordless login. Within less than a few hours it was (presumably) spewing mail or doing awful things -- long before anything went anywhere near production data or any kind of trust.
- zamalek 6y ago> [Article] They could be the work of a vigilante trying to give administrators a hard lesson in security by raining destruction on unsecured data. It could be a person attempting to prevent the data from falling into the wrong hands. Problem is: once it's deleted, you have no idea whether your data was stolen and shared. A better option would be to first send a copy to Have I Been Pwned.
- EGreg 6y agoHow does this work? Will it affect MySQL databases accessible from the Internet but secured with a long random password?
- jacekm 6y agoNo. The bot targets only unsecured Elastic databases, i.e. ones where no credentials are necessary to execute queries.
- Twirrim 6y agoDon't expose MySQL databases to the internet. Just don't. Stick an API layer in at the very least with key based auth, and only the bare minimum capabilities allowed for the user. That said, if you'd read the article you'd see that so far only unsecured MongoDB, Elasticsearch and Redis installations are being attacked so far.
- PanMan 6y agoMost SAAS db providers provide their database over the internet, but secured with a login/pass. Eg all DB's on Heroku elements marketplace work like this.
- GordonS 6y agoYou can also usually lock it down by IP address.
- GekkePrutser 6y agoYes, or they provide an internal subnet only accessible to servers from the same tenant. Usually it's double useful because usually this traffic is not charged.
- gverrilla 6y agoI'm doing my first web project (self-taught), which is the prototype for an offering me and a partner are developing to become a startup. I was about to start deployment (for the first time in my life) this week, but now I'm afraid. It's a flask app. We serve users forms (POST), then I use this input to run calculations on the server through a python script which makes queries to a MySQL db, then I return results to browser my listing a result-array dynamically using a Jinja template. Is this unsecure? Any tip or accessible reading material to help me understand this matter? We don't store credit card info or other sensitive information for now, because we didn't reach any clients yet, but final version should have at least login functionality. Any light/knowledge/consideration will be much appreciated! PS: I don't know exactly what you mean by "Stick an API layer in at the very least with key based auth" because I never used an API before and didn't know I would need something like this.
- 29athrowaway 6y agoSearch engines like shodan.io make it trivial to discover unsecured databases exposed to the Internet.
- quaintdev 6y agohttps://www.censys.io https://www.censys.io
- hobofan 6y agoWhat I don't get about Shodan: Why aren't all unsecured databases found instantly (at the moment Shodan went online), but recurring attacks/dumps like this one that rely on it? Do they update their crawl data in waves?
- onion2k 6y agoPeople make new unsecured servers.
- jcrawfordor 6y agoOne real limitation is getting data out of Shodan. Having done a few different projects that involve large-scale use of Shodan results (e.g. several hundred thousand records), this kind of thing usually ends up costing $300 for either export credits or a service plan. Sure, $300 isn't really that much to cause millions in damage, but I think it's a big factor in why we don't often see Shodan used for huge-scale malfeasance. You both have to put up the money and in paying you probably give up some identification info, and I don't know if Shodan has complied with law enforcement in the past but I can sure see them getting a warrant for "the person who just spend hundreds to export and/or query every unsecured MongoDB." Also, as a bit of an aside, the relationship between "export credits" and "query credits," and the export system and API of Shodan, are extremely confusing and just a bad bit of product design. Each one seems to be capable of things the other isn't, but they're priced on totally different systems. But really it's mostly just a matter of motivation, I think. Pulling even just thousands of entries from Shodan, writing some software to use them, and then running it in a reasonably deniable way, takes effort and is pretty slow (why we see this going for multiple days). It's not a huge amount of effort but it's enough that "script kiddie" types don't really seem to do it, you need to be motivated and spend the time on it. Contrary to security urban legend it seems like the number of people who are highly motivated to purely cause damage is not actually that large, people only put in the time if they can figure out a way to gain from it... and just deleting data doesn't really achieve that. You've got to figure out a way to hold it for ransom and/or collect and leverage sensitive data. We've seen both happening on various scales with this kind of unsecured database and we'll probably see more of both as we go forward... but keep in mind that in the ransomware game, encrypting computers is both easier (established off-the-shelf ransomware can be purchased) and probably shows higher returns, so the "professionals" aren't spending a lot of time messing around with exposed databases.
- gregschlom 6y agoSo why is the attack being called Meow?
- Nextgrid 6y agoI believe they rewrite the records in the unsecured DBs with "meow".
- detaro 6y agoBecause it deletes data and only leaves records saying "meow".
- phoe-krk 6y agoSeems like all that's left of a database after the attack is some generated indices or other data structures with their names ending with "meow".
- bdcravens 6y agoCats like to knock things off of tables.
- contrarianmop 6y agoI prefer this over having data stolen. Also as a rule of thumb never ever expose anything but port 80 and 443 if hosting a webapp. If you must expose services other than http/s then be sure to not leak its version, have it secured properly and _always_ up to date. The user running such services should also be a non privileged user, the daemon chrooted, and the OS should have appropriate process and filesystem permissions in place.
- mekkkkkk 6y ago> I prefer this over having data stolen. How do you know it wasn't?
- glenstein 6y ago>I prefer this over having data stolen. Okay, and I prefer being waterboarded over being drawn & quartered. But it doesn't mean I support the practice of waterboarding, since there's another option, namely just not waterboarding in the first place. This contrarianism is so strange to me. Data not being deleted by a bad actor is preferable to having it deleted, and I would think that would be the main takeaway here, rather than this weird descent into counterfactuals. Where does the impulse come from to bypass the normal answer, treat it like a trick question and go into contrarian mode by measuring it against counterfactuals? I think when you do that you lose sight of the most important thing here, which is the fact that data is being wantonly deleted and that it is bad that this is happening.
- rectang 6y agoIf the databases in question (Elastic, MongoDB, others) make it too easy to set up unsecured access, possibly because they default to an unsecured state on installation, then some good may come of this: The reputation hit to the database vendors should encourage them to mend their ways. If that happens, then the attack can arguably be justified despite the damage — consider all the future database installations which wouldn't otherwise have been secured which are now spared from not only destruction but theft.
- lol768 6y agoI've said it on here before, but the way in which Elasticsearch used to lock away critical security functionality (like TLS support and RBAC) behind a paid subscription whilst making just enough functionality available for free such that users could shoot their foot off is disgusting. This only ever changed after Open Distro for Elasticsearch came onto the scene and forced Elastic's hand. I entirely agree the vendors are (partially) to blame here.
- bmcahren 6y agoThis is why we are refactoring our database to be able to migrate to Amazon documentdb from MongoDB. Encryption at rest.... Pay up!
- nickjj 6y agoThis reminds me of "crackit"[0] from a few years ago with Redis. A lot of folks kept their Redis server bound to 0.0.0.0 with no firewall or published port 6379 by "accident" with Docker and by default Redis uses no password. It was a lot worse than meow because with some Redis configuration magic anyone could inject their own SSH keys onto the server. This article says Redis is affected but I would be curious to see which version of Redis was being used because they changed their default configuration after crackit was wide spread. [0]: http://antirez.com/news/96 http://antirez.com/news/96
- 1023bytes 6y agoCurrently there is crypto mining malware infecting exposed Redis servers (kdevtmpfsi)
- imglorp 6y agoThere were several redis remote execution holes, not just the config file one, so pretty much anybody with an open redis was going to get trouble. https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=redis+remote+execution+ https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=redis+remot...
- GekkePrutser 6y agoYeah one thing though with Docker is that in some cases it injects its rules into iptables before the firewall application's. I was using arno-iptables-firewall and this suffered from that, docker containers would be world accessible. In general I only bind them to localhost anyway, but I figured this out when testing. It doesn't seem to happen with UFW. But I can imagine some people know how to set up a firewall but then just assume it works and don't check. This is the kind I do feel sorry for, at least they tried to protect it.
- Polylactic_acid 6y agoThis happened to me. Was just getting started with docker and got everything working and a few months later someone had set a password on my redis database. Who knows what else happened before that. Ended up deleting the server.
- t0mmyb0y 6y agoAwesome.
- GekkePrutser 6y agoIt's not necessarily 'deleted', these Script Kitties just replaced some data with more valuable stuff. You can never have enough meows! But seriously, these guys are doing us a favour. You can bet the affected companies will not expose customer data again.
- isatty 6y ago> You can bet the affected companies will not expose customer data again. I hope so, but I seriously doubt that. Having open databases is extreme incompetency.
- pessimizer 6y agoIf this keeps happening weekly, they'll fix it. Maybe there should be a government Agency for Deleting Publicly Exposed Databases that's likely to hit any that you stand up within a week. Also, make having had a publicly exposed database deleted something that is in the public record, and highly prejudicial evidence in civil liability cases. A Department of Botnet-Suseptible IoT Device Bricking would be useful in the same way.
- weka 6y agoDidn't Equifax have open customer data back when that attack happened?
- DonHopkins 6y agoThe Cat Game is no laughing matter. https://www.youtube.com/watch?v=1rlSjdnAKY4 https://www.youtube.com/watch?v=1rlSjdnAKY4
- 0xUser 6y agoyup
- agustif 6y agoAlready waiting for meow(two)
- Chris2048 6y agoon the UFO VPN leak: > “In this server, all the collected information is anonymous and only be used for analyzing the user’s network performance & problems to improve service quality. So far, no information has been leaked.” I can't see how you can keep enough info to analyse an individual users service, without keeping logs on their access details (source/target IPs). What BS.
- p3rry 6y agoDamn, last week we were wondering where did our data went and why there are so many meow indexes! We were meowed !!!
- GekkePrutser 6y agoThe cat's out of the bag now!
- epr 6y agoThe cat's out of the bag meow!
- Havoc 6y agoMeh. Maybe it’ll get devs to pay attention to database security.
- deleted 6y ago[deleted]
- user5994461 6y agoWorks great. You can already find questions on Stack Overflow from people getting their database deleted https://stackoverflow.com/questions/63067062/elastic-search-indexes-gets-deleted-frequently https://stackoverflow.com/questions/63067062/elastic-search-... Edit: The person raising that question is working for Atlassian (Jira), looks like Atlassian got their database deleted lol
- philshem 6y agoThe top-voted answer links to this HN page. I'm stuck in an infinite loop.
- aledalgrande 6y agoYou should configure a timeout.
- inetknght 6y agoGood tree^H^H^H^Hgraph traversal algorithms have a history stack specifically to detect and deal with loops.
- red0point 6y ago1) If it‘s a tree, it ain‘t got no loops 2) The stack isn‘t to deal with loops, the „visited“ flag at each edge is there for that. The stack (for DFS, BFS would be a queue) is there to keep track of which nodes have been visited such that you can construct a path from the starting node to the one you‘re looking for. Obviously there are variants to this, depending on what you‘re actually trying to achieve with it. My point is that a stack would be a very inefficient way to deal with loops.
- inetknght 6y ago1) you're right, I edited my message to reflect that I meant a graph traversal algorithm. 2) a visited flag on an edge? That won't support simultaneous traversals. Keeping a stack is a lot more efficient than permitting only one traversal at a time.
- dillonmckay 6y agoHow do they determine ‘almost 4k’?
- afrcnc 6y agoShodan and BinaryEdge search results
- deleted 6y ago[deleted]
- kalium-xyz 6y agoI wonder if its going after RATs, heh
- macleodan 6y agoCats like knocking stuff off tables.
- BossingAround 6y agoBrilliant!
- faebi 6y agoIs it legal to access them if they are unsecured?
- bdcravens 6y agoLegality is determined by permission, so no.
- deleted 6y ago[deleted]
- alain_gilbert 6y agoDo you have permission to access HackerNews (:rolleyes:) ? You access it because it's publicly available...
- kl4m 6y agoNot any more than walking in the street and trying car doors.
- Avamander 6y agoBad comparison. This is akin to someone random walking into a restaurant and looking under the fryer and finding a dead rat and removing it with the fryer.
- bronlund 6y agoThis reminds me of the old days. Today a virus usually tries to go undetected and does a number of things, but back in the days - if you got a virus, you were fucked :)
- jb775 6y agoIf a business or org is careless enough to leave their data exposed, they deserve to be punished like this. I'd rather have my sensitive data deleted by hackers than exposed by hackers.
- 3gg 6y agoThis is bad when it comes to personal data, like the VPN provider that claimed not to be logging. Companies should spend every effort to secure people's data, and can face large fines in the event of a leak. In erasing the data, Meow is also erasing the evidence of their crimes. Instead, Meow should ransom the data and set a fine proportional to the company's size, revenue, the sensitivity of the personal data, whether that personal data should have been collected in the first place, whether that data should be public-facing, etc. Then Meow can be made a public service, perhaps paid with taxpayer money, and bring about justice.
- pmarreck 6y agoWhy must some people insist on being assholes?
- spoopyskelly 6y ago> Why must some people insist on being assholes? The ones leaving giant databases unsecured? At least they are being taught an important lesson.
- pantaloony 6y agoMy blame scale for breaches, most to least: 1) the cultural and economic forces driving everything online way before that’s anything like a good idea, 2) companies storing more than they need to, 3) the people who left it unsecured (bigco, tech startups, and anything very sensitive), 4) the people stealing data, 5) the people who left it unsecured (Smaller shops that’ve been made to feel they must be online), [large gap] 20) someone who simply deletes all the insecure data (assuming they didn’t also steal all of it)
- glenstein 6y agoWhy is the person doing the deleting so low, relatively speaking, in your ranking of people's responsibility for them doing the deleting? Also, do you think that this person or persons would refrain from deleting the data if they had the opportunity, but it qualified as a "good idea" to keep online? I.e. they might review, say, medical records, spend some time thinking to themselves whether it was 'necessary' to be online, and then decide to delete or not delete depending on their judgment?
- pessimizer 6y agoFor me, it's because the odds of this person showing up quickly approach 1 as time approaches infinity, and that person's effect would be nil if it weren't for necessary causes 1) through 19). Blaming the person that hacked you is like blaming the individual rock that sinks your boat when you navigate too close to a rocky shore. The rock may have done 100% of the damage to your boat, but if it hadn't been that rock, it would have been another one.
- nautilus12 6y agoWhy is mongodb seem to show up alot with this. Does their default set up hide some unsecured users? Its been a while but I dont remember that being in there.
- akx 6y agoNo, their default sets up no authentication at all IIRC. Combined with Dockerized installations punching through some firewall setups (as discussed elsewhere), you'll get meowed.
- achillean 6y agoBy default though, MongoDB will only listen on localhost and I believe it'll show you a big warning on boot up if you don't have authentication configured. They used to listen on 0.0.0.0 by default but that was fixed many years ago. And this issue doesn't just affect MongoDB - imo since the "webscale" days it's been a favorite to knock on but the public exposure of data happens across many technologies. Here's a comparison with a few others: https://blog.shodan.io/elastic-data-exposure-grows-to-3-2-pb/ https://blog.shodan.io/elastic-data-exposure-grows-to-3-2-pb...
- b123400 6y agoIf this turns out to be an effective lesson on security, systems should implement their own meow to protect their users. E.g. A database That intentionally removes itself if the default password/an insecure password is used, with an easy-to-follow guide in error log on how to properly configure it.
- hinkley 6y agoIf memory serves, Postgres will only listen on 127.0.0.1 unless the admin password has been set. All software should work like that.
- steffan 6y agoMongoDB listens only on localhost by default since 3.6 (2017)
- hinkley 6y agoYou are allowed to judge people for taking far, far too long to do the right thing. It indicates a pattern of poor judgement, which speaks to trust. You know they are going to let you down each time a new issue comes up. Faulting people for being cautious around such bad actors (which I'm not saying you're doing, but the response will) speaks to your judgement, not the vendor's.
- 908087 6y agoIf this results in unsecured private data vanishing, and people who have no business handling that data taking a hit, more power to them.
- bcrosby95 6y agoPeople are talking about more responsible disclosure. Is it feasible to even track down the owners of 4,000 different unsecured databases, much less go through the whole process with them to ensure the database is properly secured?
- akx 6y agoSome of these attacks leave a calling card sort of thing, e.g. a database with a document that says "hey, lock your stuff up". That's more or less the best you can do without unreasonable effort, and there's no guarantee the database's owners will ever see the extra database unless you also destroy stuff on the way to make them pay attention...
- hinkley 6y agoWhen that SQL Server worm was going around I had three or four different machines spamming my firewall trying to search for more victims, but I was only able to track one of the IP addresses back to contact information. That person was very grateful for the heads up, but the other three were SOL.
- vulcan01 6y agoI've got some Heroku projects, which don't have a static ip. How do I protect myself against this?
- Linkd 6y agoSimply set a secure password on any DB instances exposed to the internet.
- steffan 6y agoIf you're using MongoDB Atlas, you can allow connections only from a specific subnet. Also, you should of course set a password or use x.509 certs. If you're hosting your own DB on a cloud provider, connect using a VPC / Heroku's Private Space Peering to keep your database off of the internet.
- cdrini 6y agoIt's stuff like this that reminds me that the internet is in many ways still in a loosely regulated, "Wild West" state. This is pretty clearly willful destruction (I.e. vandalism; https://legal-dictionary.thefreedictionary.com/Willful+damage https://legal-dictionary.thefreedictionary.com/Willful+damag...). It's illegal in the real world, and should be illegal in the digital world. A lot of people are saying that organizations that had these DBs in public "had it coming", or "now they'll learn." What's a real world parallel for this? If an organisation is putting its customers at risk, you can report them. In these cases, companies with insecure data stores are putting their customers at risk by exposing their data. Is there anyone you can report them to? Is there any organisation that will hold them accountable to actually make changes? I'd also note that not all DBs contain other people's data. Those have no moral concerns with bring public. There is a risk that someone will destroy it, but I'd say that's the same risk taken with public art or something. Yes it's public; yes someone can destroy it; yes it's illegal for someone to destroy it (even though it's public); no, the fact that it's public is not illegal.
- webo 6y agoWho do you think should regulate the “public”? ISPs, police, government?
- cdrini 6y agoI don't know :( But this feels like some sort of terrorist tactic, and I don't think this should be the way things on the internet are regulated either.
- cdrini 6y agoActually, that's one of things that makes this frustrating. Because there is no real regulation, a group/individual decided to "become" the law. The became lawmaker, judge, and executioner. They decided what was illegal, collected the guilty, and punished them for it. That's what makes this feel like a "Wild West" situation. The made themselves regulators of the internet.
- 6y ago
- AznHisoka 6y agoIs there an inexpensive service out there that does “mock” attacks if you give it a bunch of host names and ports? I know it’s something you could create yourself but would be nice to have a third party try to connect to your databases and immediately alert you if it was able to gain access. Would especially be useful if you were tinkering with firewall/security settings and accidentally opened something up.
- stjo 6y agoMetasploit kinda fits the description
- edoceo 6y agoRun OpenVAS against your infrastructure. It's free cost, nearly free in time. Edit: I also do this as a service, have for years, and hammer my own system monthly.
- achillean 6y agoShodan Monitor will do it and if you're only keeping track of <= 16 IPs then you would just need the membership which is a one-time payment of $49 (i.e. no subscription cost) for a lifetime account upgrade (https://www.shodan.io/store/member https://www.shodan.io/store/member). You just provide an IP/ network/ domain and we'll notify you if anything changes or becomes vulnerable. It's basically Google Alerts but for network ports: https://monitor.shodan.io https://monitor.shodan.io Disclaimer: I'm the founder of Shodan.
- joana035 6y agoLets return the computers back to sysadmins ;-)
- andrewstuart 6y agoCan someone how/explain why databases are left open?
- quasarj 6y agoIgnorance.
- achillean 6y agoShort answer: cloud images with poor defaults. I've written about this a few times before and the problem hasn't really changed since the article was posted: https://blog.shodan.io/its-the-data-stupid/ https://blog.shodan.io/its-the-data-stupid/
- neop1x 6y agoBecause the open-source version of Elastic does not contain any security (not even a basic auth) and requires at least a reverse-proxy in front of it which adds difficulty of connecting two things together. And Elastic-licensed Elastic with Security needs to be configured by chaning its config file. That is apparently too complicated for most "IT specialists". :) `sudo apt-get install elasticsearch && sudo systemctl start elasticsearch` and they are done.
- Grue3 6y agoDocker overriding iptables rules, in my case. I was using somebody else's project distributed via docker-compose config, which made the port for elasticsearch public, which I was not aware of (I don't normally use docker or elasticsearch). Luckily I was able to regenerate the data stored in elasticsearch, though I had to do it twice because it got wiped again after regeneration and then I had to google what the hell is going on.
- davidbrennerjr 6y agoI can't believe people are victim blaming the db admins for not knowing about vulnerability. What good comes of destroying the db instead of talking about the vulnerability to the open source projects? Coincidentally shodan; that I've never heard of.
- tgsovlerkhgsel 6y agoThere's a difference between a vulnerability, and a common misconfiguration that usually comes from a "make it work first, security later" mindset. The good that comes from destroying the DB is: a) the data is no longer exposed to the Internet, where more malicious actors could take it, affecting the customers of the incompetent company b) ignoring it stops being a viable option - leaking your customer's data all over the place often doesn't have sufficiently obvious and severe consequences for the company doing the leaking to discourage it. Disruption that breaks production will get their attention, and they likely will secure their database in the future. (No moral or legal judgement regarding this action, just answering the "what good comes of it" question.) Edit: Also, someone commented further below on the difficulty of doing it the right way - it's hard to contact the companies, and it's even harder to get them to actually listen and fix it instead of ignoring it or trying to "shoot the messenger". This approach may be wrong and/or illegal, but it it much likely to actually draw the attention of the right people, and prevent them from simply ignoring the problem. The companies running those open databases aren't just victims; they're also perpetrators of privacy violations. In many cases, they're even collecting data for a purpose that the data subject receives no benefit from.
- heretoo 6y agoSo, you've answered "what good comes of it". For completeness, would you mind answering, "what bad comes of it?"
- dilandau 6y agoVictims are not the DB admins. Victims are the people whose private data, or data they expect to be private, is exposed due to developer incompetence.
- 6y ago
- monksy 6y agoThis is what happens when you lay off all of your sysadmins because "the cloud", move that role to devops and then downsize that to a subduty of a developer.
- ShaneMcGowan 6y agoBut the profits...
- acdha 6y agoI’ve seen just as many sysadmins do this as developers. It’s not a question of job title as a psychological pitfall (people who are looking for things to succeed don’t ask when they should fail) and companies not specifically retaining people with security experience because they cost more.
- stjohnswarts 6y agoIt can be though. Downsizing and getting rid of specialists certainly hurts companies. There are only so many hours in the day and that desperate guy working 14-16 hours a day because of covid downsizing is eventually going to eff up no matter how talented she is.
- acdha 6y agoI’m not sure exactly what you’re disagreeing with. My point was just that it’s not useful to direct criticism at a job title when there are so many examples of failures by people with any given title. I’ve seen people who are ostensibly pen-testers or auditors blithely telling others to click through important warnings or have a root-on-all-machines password to make their work easier. Downsizing and other false economies are definitely a contributing factor. Security and reliability are easy to dismiss as expensive overhead until they suddenly aren’t.
- thrownaway954 6y agoi'm sure it's not that. most likely they are databases that development setup for testing or developing a quick server and just forgot to hand it over to sysops or dbas. happened all the time where i use to work.
- baxtr 6y agoI wonder about the motive. Why would anybody do this without blackmailing or even telling people. Maybe it was a frustrated sysadmin... :/
- foolfoolz 6y agowhy would anyone want to have their work be talked about all across the internet and become part of internet history??
- baxtr 6y agoFair enough!!
- quickthrower2 6y agoFor fun.
- Bootwizard 6y agoWhat exactly does "unsecured" mean in this sense? The article never explains the attack
- steffan 6y agoStarted up exposed to the internet and listening on 0.0.0.0... ...and also not enabling a password
- dt3ft 6y agoAfter having read a number of articles talking about data leaks on a gigantic scale, I decided to check it out. Because shodan is not free to use/behind a paywall, I wrote a simple windows console tool which scans all known Azure subnets for unsecured elasticsearch instances and logs the results. I was baffled by the amount of instances this tool found within the first few hours :( To say that security in IT is getting out of control would be an understatement...
- achillean 6y agoDoing aggregate queries is free - only if you want to download actual data do we start charging money. You could just do the following via the CLI using a free account: $ shodan count product:Elastic org:Azure This entire website is powered by a free API key: https://exposure.shodan.io https://exposure.shodan.io
- userbinator 6y agoI wonder if you can find a remote code execution vulnerability in client libraries for one of these databases, and set up a few honeypot databases... you might be able to catch who's doing it and retaliate. The legalities of doing that are certainly questionable, but then again, so is this.
- heretoo 6y agoHippocratic Oath: "First, do no harm".
- tremon 6y agoAnd the Hippocratic oath applies to online vigilantes how, exactly? Right now, I think these actions are causing more good than twenty years of lacklustre legislation have done, worldwide.
- heretoo 6y agoThat was aimed at everyone on this thread that feels comfortable with deleting databases that they don't own. Vigilantes make their own choices, but professionals are judged by their reputation. As I've said elsewhere, I challenge anyone, especially professionals, to tweet "I will delete your data if you don't secure it" and to add it to your resume/CV as a strength.
- heretoo 6y agoIf you really believe this action is warranted, as I've read on this thread, I challenge you to tweet under your real name "I will delete your data if you don't secure it", and add it to your resume/CV as one of your strengths.
- MauranKilom 6y agoThe part that confuses me here is that everybody seems to take in stride that all these public-facing databases are already tracked and indexed. Like, how does https://www.shodan.io/search?query=meow+indices https://www.shodan.io/search?query=meow+indices know all this? What am I missing here? Is this attack literally "attempt access each database listed on shodan.io and destroy it if that works"? I might be missing some major aspect (I certainly hope so), but isn't this like wondering why all those fireworks that people keep storing on the streets were eventually set off by some kid with a mask? Why isn't the question "why didn't this happen sooner"?
- achillean 6y agoIt has already happened in the past. Repeatedly. There's news coverage about this at least once a year. And it doesn't require using Shodan as there are plenty of open-source tools for scanning the Internet nowadays. For example, this was from the same news website a few years ago: https://www.bleepingcomputer.com/news/security/massive-wave-of-mongodb-ransom-attacks-makes-26-000-new-victims/ https://www.bleepingcomputer.com/news/security/massive-wave-... I've also written about it many times: https://blog.shodan.io/its-the-data-stupid/ https://blog.shodan.io/its-the-data-stupid/ https://blog.shodan.io/its-still-the-data-stupid/ https://blog.shodan.io/its-still-the-data-stupid/ https://blog.shodan.io/the-hdfs-juggernaut/ https://blog.shodan.io/the-hdfs-juggernaut/ https://blog.shodan.io/elastic-data-exposure-grows-to-3-2-pb/ https://blog.shodan.io/elastic-data-exposure-grows-to-3-2-pb...
- MauranKilom 6y agoJeez, that's a pretty impressive dumpster fire. And it's been going for half a decade. Kudos for keeping track of it and periodically doing your part in reminding the world.
- sarasasa28 6y agowhy are only meme databases affected?
- scarface74 6y agoELI5: Way back in the early 2000s I was a young mid level developer and we had a SQL Server backed solution. There was a wide spread attack on Sql Server installations that didn’t change the default blank SA password. We were one of the companies that didn’t. But, even then I knew not to have a publicly accessible database server. We just didn’t give the server a public IP address. Nothing fancy. We weren’t affected but I immediately changed the password. Fast forward to 2018. The company I worked for was just starting to ramp up an in-house development staff led by a new CTO. Everything had been outsourced to a foreign agency. They had a publicly accessible ElasticSearch cluster. I wasn’t on the team responsible for it, but I know that the architect on the team knew better. Even though he didn’t setup the original cluster, he knew it was insecure and just didn’t prioritize recreating it inside our VPC. Of course we got hacked and someone deleted everything in it. Then they decided to go ahead and recreate it inside the VPC. Luckily we didn’t use ES as a primary store and we were just offline all day while we ran the process to repopulate the cluster from our Mysql database. Why do people keep making the same mistake? I was definitely not any world class software architect at 25 years old, but even I knew to be cautious about giving servers public IP addresses unnecessarily.
- asciimov 6y ago> Why do people keep making the same mistake? Because there are always new developers showing up that haven't been taught. (Eternal September if you will) The real solution would be: 1. We are past the point were our practice needs professional licensure. We need standards, a governing body, and ethics. 2. Those above items need to be taught to new developers. How long has security been an after thought to CS degree programs? I know I never touched it in an academic setting. We didn't even have a class that covered it. You wanted to learn about it you had to seek it out. 3. Vendors to do the right thing and stop offering default passwords. That isn't going to happen, so we have to force them to, either trough legislation or through other means.
- scarface74 6y agoBut I bet a new college grad can reverse a binary tree on the whiteboard and do “leetCode hard” problems in their sleep....
- Zenst 6y agoGiven some VPN's and other secure services that got used in Hong Kong turned out to have open logs as just resold services. So one wonders how many people will be positively effected by this.
- snorrah 6y agoIt’s 2020, where security should be at the forefront of almost any tech endeavour. It’s not something to think about afterwards, not any more. If, given the frequent and public attention to hacked data, you aren’t thinking about how to make sure your data is safe, there really can’t be any sympathy when you get hit by an attack that relies on zero security applied to your database. C’mon, do we as an industry really learn NOTHING from all the hacks we’ve lived through ?
- ddrt 6y agoNot to be disrespectful it is there a more reputable source that doesn’t jackhammer ads down the users throat every other paragraph?
- northwest65 6y agoIf you see ads on that page you are interneting wrong. I'd really encourage you to install an adblocker.
- pabs3 6y agoI wonder what proportion of these are just PII that should never have been collected in the first place?
- dredmorbius 6y agoAny statements by Shay Banon? Crickets AFAICT: https://twitter.com/kimchy https://twitter.com/kimchy Also: https://twitter.com/elastic https://twitter.com/elastic
- woah 6y agoSeems like kind of a public service
- mulmen 6y agoSeem like this could be easily reconfigured to do the opposite. Leave the databases but overwrite all the existing data then write dummy data until disk is exhausted. Does that cross another ethical line?
- dvfjsdhgfv 6y agoIt took way too long. When you have a company that builds a great product with no security whatsoever and makes their business model based on selling the security module on it and changes their behavior only when threatened by a competing open source product, you have to wonder when the catastrophe comes. Note I don't blame anyone, it was just bound to happen.
- kabacha 6y agoMight be very immature of me but attacks like this still make me crack up as if I was still a teen in YouGotPwned web times.
- dependenttypes 6y agoI think that this is an instance of ethical hacking. They hurry up to remove any and all instances of PII before some hostile actor scrapes them while at the same time punishing the people who leave their servers open without caring for their costumers. To whoever is doing that: you are doing god's work, please keep it up.
- ComodoHacker 6y agoThere's some gray hat job well done here.
- 0xUser 6y agoGood, probably for the better.
- sova 6y agoHTTP Delete makes a come back in spectacular fashion