avatarTeri Radichel

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

5065

Abstract

<div><h3>An unprotected 140+ GB MongoDB database led to the discovery of a huge collection of 808,539,939 email records, with…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*n_etGm7oWIsXl8zt.png)"></div> </div> </div> </a> </div><blockquote id="d5b9"><p>Another day, another massive MongoDB exposure. This time, a security researcher has discovered a public-facing database with over 275 million records containing personal information on citizens in India.</p></blockquote><div id="ee00" class="link-block"> <a href="https://nakedsecurity.sophos.com/2019/05/10/275m-indian-citizens-records-exposed-by-insecure-mongodb-database/"> <div> <div> <h2>275m personal records swiped from exposed MongoDB database</h2> <div><h3>Another day, another massive MongoDB exposure. This time, a security researcher has discovered a public-facing database…</h3></div> <div><p>nakedsecurity.sophos.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Yu1FKz-Vb_idEA_G)"></div> </div> </div> </a> </div><blockquote id="9345"><p>MongoDB Apocalypse: Professional Ransomware Group Gets Involved, Infections Reach 28K Servers</p></blockquote><div id="a3ae" class="link-block"> <a href="https://www.bleepingcomputer.com/news/security/mongodb-apocalypse-professional-ransomware-group-gets-involved-infections-reach-28k-servers/"> <div> <div> <h2>MongoDB Apocalypse: Professional Ransomware Group Gets Involved, Infections Reach 28K Servers</h2> <div><h3>The number of hijacked MongoDB servers held for ransom has skyrocketed in the past two days from 10,500 to over 28,200,…</h3></div> <div><p>www.bleepingcomputer.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*lbCkeikV12HGkOTj.jpg)"></div> </div> </div> </a> </div><blockquote id="b0f5"><p>Discovered by Comparitech’s researcher Bob Diachenko on June 18, 2019; the database contained personal sensitive information of over 188 million people. According to Diachenko’s analysis, some of the records in the database belonged to users from LexisNexis and Pipl.</p></blockquote><div id="516d" class="link-block"> <a href="https://www.hackread.com/unprotected-mongodb-leaks-users-data-from-sensitive-search-engine/"> <div> <div> <h2>Unprotected MongoDB leaks 188m users' data from sensitive search engine</h2> <div><h3>Another day, another data breach; this time, a security researcher has discovered a massive trove of data hosted on an…</h3></div> <div><p>www.hackread.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*wtja59urrd8rF-mJ.jpg)"></div> </div> </div> </a> </div><blockquote id="6387"><p>…unsecured MongoDB server that was leaking the personal details of nearly 11 million users. The server appears to belong to an email marketing firm based in California.</p></blockquote><div id="d342" class="link-block"> <a href="https://www.zdnet.com/article/mongodb-server-leaks-11-million-user-records-from-e-marketing-service/"> <div> <div> <h2>MongoDB server leaks 11 million user records from e-marketing service | ZDNet</h2> <div><h3>On Monday, a security researcher specialized in finding exposed databases has identified an unsecured MongoDB server…</h3></div> <div><p>www.zdnet.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*-hwVaxv3Jjbba9Ps.png)"></div> </div> </div> </a> </div><blockquote id="316b"><p>The 12,564 sabotaged databases make up roughly 20 percent of the 63,000+ publicly configured MongoDB identified via BinaryEdge, the report continues.</p></blockquote><div id="559b" class="link-block"> <a href="https://www.scmagazine.com/home/security-news/cybercrime/report-hacking-group-wipes-content-from-over-12000-open-mongodb-databases/"> <div> <div> <h2>Hacking group wipes content from over 12,000 open MongoDB databases</h2> <div><h3>In less than a month's time, the "Unistellar" hacking group has reportedly accessed over 12,000 unsecured MongoDB…</h3></div> <div><p>www.scmagazine.com</p></div>

Options

     </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*8hgXQafzUA6HVyk4)"></div>
          </div>
        </div>
      </a>
    </div><blockquote id="bc8c"><p>A MongoDB database containing the personal records of around 5 million individuals has been left exposed on the internet.The database contained personal information and health data and belonged to MedicareSupplement.com, a website run by TZ Insurance Solutions which helps individuals find a Medigap insurance plan.</p></blockquote><div id="8cfa" class="link-block">
      <a href="https://www.hipaajournal.com/5-million-records-exposed-due-to-unsecured-mongodb-marketing-database/">
        <div>
          <div>
            <h2>5 Million Records Exposed Due to Unsecured MongoDB Marketing Database</h2>
            <div><h3>Share this article on: A MongoDB database containing the personal records of around 5 million individuals has been left…</h3></div>
            <div><p>www.hipaajournal.com</p></div>
          </div>
          <div>
            <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*8D3hgaWdbx6N4mGS)"></div>
          </div>
        </div>
      </a>
    </div><p id="a852">There are so many more examples. These are just a few. Exposed MongoDB and other databases are one of the many cloud threats I cover in my <a href="https://2ndsightlab.com/cloud-security-training.html">cloud security class</a>. I also explain what to do about it, not just at a tactical implementation level, but at the organizational level when dealing with Governance, Risk, and Compliance (GRC).</p><p id="2703">I often wonder if these databases are intentionally exposed, by accident, coding error, or malware. <b>Secure defaults help.</b> Some cloud provider defaults are more open than others, but in any case, it is the customer’s responsibility to ensure they don’t expose your data publicly on any cloud platform. You need to understand what data you expose to the Internet and how. You also need to secure and monitor all database connections if you care about the data in your database.</p><p id="d66d">In the cloud, sometimes the network implementation falls to developers. They need the training to learn how to do it properly if they are going to be responsible for it. Otherwise, companies need to assign a dedicated networking team who understands the <a href="https://readmedium.com/high-risk-ports-the-chink-in-your-network-armor-395a31e478ca">risk posed by open ports</a> as I wrote about in another post. Implementing networking in the cloud seems simple at first. Open a port. It works! Implementing secure networking is another matter.</p><p id="ce01">Networking in the cloud is crucial for security. Some cloud providers make it seem easy to connect to cloud resources, but do you fully understand what you are exposing in exchange for that ease of use? Understanding this and other vital aspects of networking in the cloud is why I have a full day of network security in my class — so you can learn how to do it correctly — and why it matters down to the packet level. Stay tuned for tips on securing your databases, pentesting, implementing cloud networking on the <a href="https://2ndsightlab.com">2nd Sight Lab </a><a href="https://medium.com/cloud-security">Cloud Security</a> blog.</p><p id="3a49">Follow for updates.</p><p id="4a3a">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2019</i></p><div id="8b5f"><pre><span class="hljs-section">About Teri Radichel:
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab</pre></div><div id="caae"><pre><span class="hljs-section">Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation</pre></div><div id="5a42"><pre>Follow <span class="hljs-keyword">for</span> more stories like <span class="hljs-keyword">this</span>:

❤️ Sign Up my Medium Email List ❤️ Twitter: <span class="hljs-meta">@teriradichel</span> ❤️ LinkedIn: https:<span class="hljs-comment">//www.linkedin.com/in/teriradichel</span> ❤️ Mastodon: <span class="hljs-meta">@teriradichel</span><span class="hljs-meta">@infosec</span>.exchange ❤️ Facebook: 2nd Sight Lab ❤️ YouTube: @2ndsightlab</pre></div><figure id="faf5"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*H9Ew1KCl-29nZiPR.jpeg"><figcaption></figcaption></figure></article></body>

Amazon DocumentDB Network Access — Why the VPC?

Billions of reasons why networking is vital for cloud security courtesy of MongoDB

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

⚙️ Part of my series on Automating Cybersecurity Metrics. The Code.

🔒 Related Stories: AWS Security | DevOps | Network Security

💻 Free Content on Jobs in Cybersecurity | ✉️ Sign up for the Email List

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I was recently at the AWS Developer Influencer Summit in Seattle at Amazon, and I heard someone ask why Amazon DocumentDB requires a VPC. DocumentDB is an AWS document database, as the name suggests, with MongoDB compatibility. Here are billions of reasons why requiring a VPC for this service is an excellent choice, some with ransomware as a bonus. I don’t need to re-write what others have already reported. Instead, I refer you to the links below. A synopsis of why this is so important follows.

Choice Hotels — 700,000 records.

2.1 million records belonging to well-known Mexican publisher and bookseller, Librería Porrúa held for ransom.

A database containing 37,000 records on individuals from Australia and New Zealand has been uncovered, with the exposed data connected to clinical trials.

An unprotected 140+ GB MongoDB database led to the discovery of a huge collection of 808,539,939 email records, with many of them also containing detailed personally identifiable information (PII).

Another day, another massive MongoDB exposure. This time, a security researcher has discovered a public-facing database with over 275 million records containing personal information on citizens in India.

MongoDB Apocalypse: Professional Ransomware Group Gets Involved, Infections Reach 28K Servers

Discovered by Comparitech’s researcher Bob Diachenko on June 18, 2019; the database contained personal sensitive information of over 188 million people. According to Diachenko’s analysis, some of the records in the database belonged to users from LexisNexis and Pipl.

…unsecured MongoDB server that was leaking the personal details of nearly 11 million users. The server appears to belong to an email marketing firm based in California.

The 12,564 sabotaged databases make up roughly 20 percent of the 63,000+ publicly configured MongoDB identified via BinaryEdge, the report continues.

A MongoDB database containing the personal records of around 5 million individuals has been left exposed on the internet.The database contained personal information and health data and belonged to MedicareSupplement.com, a website run by TZ Insurance Solutions which helps individuals find a Medigap insurance plan.

There are so many more examples. These are just a few. Exposed MongoDB and other databases are one of the many cloud threats I cover in my cloud security class. I also explain what to do about it, not just at a tactical implementation level, but at the organizational level when dealing with Governance, Risk, and Compliance (GRC).

I often wonder if these databases are intentionally exposed, by accident, coding error, or malware. Secure defaults help. Some cloud provider defaults are more open than others, but in any case, it is the customer’s responsibility to ensure they don’t expose your data publicly on any cloud platform. You need to understand what data you expose to the Internet and how. You also need to secure and monitor all database connections if you care about the data in your database.

In the cloud, sometimes the network implementation falls to developers. They need the training to learn how to do it properly if they are going to be responsible for it. Otherwise, companies need to assign a dedicated networking team who understands the risk posed by open ports as I wrote about in another post. Implementing networking in the cloud seems simple at first. Open a port. It works! Implementing secure networking is another matter.

Networking in the cloud is crucial for security. Some cloud providers make it seem easy to connect to cloud resources, but do you fully understand what you are exposing in exchange for that ease of use? Understanding this and other vital aspects of networking in the cloud is why I have a full day of network security in my class — so you can learn how to do it correctly — and why it matters down to the packet level. Stay tuned for tips on securing your databases, pentesting, implementing cloud networking on the 2nd Sight Lab Cloud Security blog.

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2019

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
Cloud Security
Aws Documentdb
Mongodb
Data Breach
Aws Security
Recommended from ReadMedium