id: mongodb-unauth info: name: MongoDB - Unauthenticated Access author: pdteam severity: high description: MongoDB was able to be accessed with no password. Note that MongoDB does not require a password by default. reference: - https://github.com/orleven/Tentacle - https://book.hacktricks.xyz/pentesting/27017-27018-mongodb - https://www.mongodb.com/features/mongodb-authentication remediation: Enable Authentication in MongoDB metadata: max-request: 1 tags: network,mongodb,unauth,misconfig tcp: - inputs: - data: 480000000200000000000000d40700000000000061646d696e2e24636d6400000000000100000021000000026765744c6f670010000000737461727475705761726e696e67730000 type: hex host: - "{{Hostname}}" port: 27017 read-size: 2048 matchers: - type: word words: - "totalLinesWritten" # digest: 4b0a00483046022100ce2c20315ae008c5fb000b351db2fccc181974c7211b4ccc5c385855eca8817002210094df27335a0eb5ae5d5341bd5c5386f0052b1b7922450d4ce5bedee3568864f5:922c64590222798bb761d5b6d8e72950