Account [email protected] found in thousands of MongoDB databases

Dutch security researcher Victor Gevers stated that he discovered the hand of the Kremlin administrative account [email protected] in more than 2000 open MongoDB databases owned by Russian and even Ukrainian organizations.

Admin@kremlin.ru account found in thousands of MongoDB databases

Among the discovered open MongoDB databases were the bases of Walt Disney Russia, Stoloto, TTK-North-West and even the Ministry of Internal Affairs of Ukraine.

Admin@kremlin.ru account found in thousands of MongoDB databases
Admin@kremlin.ru account found in thousands of MongoDB databases
Admin@kremlin.ru account found in thousands of MongoDB databases
Admin@kremlin.ru account found in thousands of MongoDB databases

The researcher immediately made the only possible conclusion [sarcasm] – the Kremlin, through this account, controls the finances of Russian business.

True, all these discovered MongoDB databases were installed with default settings, and anyone had read and modify permissions (Create, Read, Update and Delete).

Regular news about individual cases of data leaks are promptly published on the channel information leaks.

Source: habr.com

Add a comment