4 ms·
I guess this is only a real problem if you're exposing your MongoDB instance to the internet.
by nickporter 14y ago
I guess this is only a real problem if you're exposing your MongoDB instance to the internet.
- rambot 14y agoI suspect a lot of people are using MongoDB as the database backend to their web applications or services, so they are probably being indirectly exposed to the Internet. (Just like your Postgres or MySQL database.)
- just2n 14y agoI've never exposed a Postgres or MySQL database directly to the internet, either. They're always listening to localhost connections only, and the only code that gets to make direct calls into them is my code, which means input sanitization prevents attacks like this. The same goes for my use of MongoDB. Though I am curious if anything similar exists for CouchDB, as they seem to be encouraging dangerous configurations like that.
- rambot 14y agoSame. I was trying to suggest the attack vector most people would encounter is the web application MongoDB is servicing.
- deleted 14y ago[deleted]
- achillean 14y agoBy default, I believe MongoDB listens on 0.0.0.0 which means that servers unprotected from a firewall will expose their MongoDB database to the Internet. Shodan confirms that there are at least 31,000 public instances of MongoDB on the Internet at the moment (source: http://www.shodanhq.com/search?q=port%3A28017 http://www.shodanhq.com/search?q=port%3A28017).
- ehsanf 14y agoWow. That's a lot of servers exposed. I bet majority of them have the application/web server running on the same host. I think they should change the default to 127.0.0.1 and let people knowingly expos them to outside of localhost.
- rambot 14y agoIt sounds like they listen on localhost by default (http://docs.mongodb.org/manual/reference/mongod/#options http://docs.mongodb.org/manual/reference/mongod/#options), though i'm not sure if that's always been the case. It's also possible installers change the default behaviour. (i.e. when you install via apt, yum, homebrew, etc.)
- achillean 14y agoGood point, it might have changed recently and last I installed it on Ubuntu it listened on 0.0.0.0. It certainly would make a lot more sense to listen to localhost by default, which is what most daemons do.
- sandstrom 14y agoI remember highlighting this problem >3 years ago https://jira.mongodb.org/browse/SERVER-207 https://jira.mongodb.org/browse/SERVER-207 (though it seems that it wasn't fixed when this issue was closed, so probably later https://jira.mongodb.org/browse/SERVER-697 https://jira.mongodb.org/browse/SERVER-697)
- tedchs 14y agoIMHO, Mongo listening on 0.0.0.0 (i.e. all interfaces) is a reasonable default. Most production deployments are going to run Mongo on a separate box from the app server, particularly if a replica set is used. This normally does not lead to Internet exposure because folks have IPTables, EC2 Security Group rules, or other firewall filtering that only allows desired traffic.