Unauthenticated Mongo DB
PENTESTING MONGODB
> show dbs
admin 0.000GB
config 0.000GB
local 0.000GB
> use config
switched to db config
> show collections
system.sessions
> db.system.sessions.find()
> show dbs
admin 0.000GB
config 0.000GB
local 0.000GB
> use admin
switched to db admin
> show collections
system.version
> db.system.version.find()
{ "_id" : "featureCompatibilityVersion", "version" : "3.6" }
CONFIGURING AUTHENTICATION
1. CREATING AN ADMIN USER

2. ENABLE ACCESS CONTROL
3. RESTART MONGODB
REFERENCES
Last updated