Skip to content

Instantly share code, notes, and snippets.

@khoan
Created September 11, 2017 12:05
Show Gist options
  • Save khoan/5740d7ad08beb87641b5b2fc6320cc7a to your computer and use it in GitHub Desktop.
Save khoan/5740d7ad08beb87641b5b2fc6320cc7a to your computer and use it in GitHub Desktop.
mongoDB compromised
$ ssh [email protected]
(stage) $ mongo
> show dbs
DATA_HAS_BEEN_BACKED_UP 0.078GB
admin (empty)
bam 0.953GB
> use DATA_HAS_BEEN_BACKED_UP
> db.getCollectionNames()
[ "README_PLS", "system.indexes" ]
> db.README_PLS.find()
{ "_id" : ObjectId("59a9ccf47ef7ce63cc2535c4"), "email_address" : "[email protected]", "bitcoin_address" : "1Mk61Q8squW8WjSWp3qEAYL6pu9TR1Cro9", "note" : "If you want to recover your data, then send 0.05 BTC to bitcoin-address and send your IP to our email. You don't want that your users/customers to know that you have a data leak, right?" }
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment