Hacker News new | past | comments | ask | show | jobs | submit login

This talks about misconfigured rsync being the vector.

However, the researcher that found it says:

"The search engine at Shodan.io had indexed their IPs as running publicly accessible MongoDB instances"[1]

The screenshot looks like some kind of mongo explorer type UI: http://imgur.com/DzNthuy Probably MongoVue: https://mongopi.files.wordpress.com/2012/11/mongovue.png

So it appears to be the "mongo installed with no password, and open to the internet" thing again.

[1]https://www.reddit.com/r/apple/comments/3wq9fc/massive_data_...




That post is a year old... I don't think it's talking about the same breach.


Ah, wow. My mistake then. Interesting that MacKeeper is related to both.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: