mongo 数据库被黑了,各位 V 友怎么做网站安全防护的?

2019-11-05 11:27:02 +08:00
 walker001

db.HOW_TO_RESTORE.find();

{ "_id" : ObjectId("5d95544778e531762eb557c2"), "1" : "localbitcoins.com", "2" : "payments.changelly.com", "3" : "wirex.com", "4" : "coinmama.com", "5" : "paxful.com", "__" : "", "google" : "or google it - buy bitcoins via credit card" }

{ "id" : ObjectId("5d95544778e531762eb557c1"), "What_happend" : "Your DB was saved and archived, you have 7 days to restore it.", "" : "", "How_to_restore" : "Send 0.1 Bitcoin to address bellow", "pay_to_btc_address" : "164UY4sPw9GzdqGdwR4fKnM7S7yVM29uy2", "send_mail" : "email to mongowant@protonmail.com with payment transaction id, your base name and ip address of your mongodb server.", "email_to" : "mongowant@protonmail.com", "get_db_back" : "You will get your db archive back immediately right after we receive an email and check payment.", "TIME" : "you have 7 days to pay, then DB will deleted because of storage costs.", "__" : "", "Where_to_buy_btc" : "List below of exchanges where you can buy BTC" }

4186 次点击
所在节点    站长
6 条回复
wangkun025
2019-11-05 11:35:27 +08:00
大哥,你好像付款了
向现实低头
walker001
2019-11-05 11:38:34 +08:00
@wangkun025 哈哈哈,我那小破站都没几个人访问,数据不多
qq316107934
2019-11-05 11:39:05 +08:00
别付款,一般都是直接删库的,说有备份都是假的。
qq316107934
2019-11-05 11:39:49 +08:00
mongo 端口不要暴露到外部,定期跑任务 dump 备份然后加密压缩下就行了。
wangkun025
2019-11-05 11:54:05 +08:00
@walker001 那个比特币的收款地址,已经收到钱了
renmu
2019-11-05 13:37:02 +08:00
你是不是开放到外网之后数据库没有加密码,MongoDB 默认没有密码,我之前也被黑了一个

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/616389

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX