diff --git a/modules/auxiliary/scanner/mongodb/mongodb_login.rb b/modules/auxiliary/scanner/mongodb/mongodb_login.rb index c3ab98e406..3a66283f27 100644 --- a/modules/auxiliary/scanner/mongodb/mongodb_login.rb +++ b/modules/auxiliary/scanner/mongodb/mongodb_login.rb @@ -46,6 +46,14 @@ class Metasploit3 < Msf::Auxiliary do_login(user, pass) } else + report_vuln( + :host => rhost, + :port => rport, + :name => "MongoDB No Authentication", + :refs => self.references, + :exploited_at => Time.now.utc, + :info => "Mongo server has no authentication." + ) print_good("Mongo server #{ip.to_s} dosn't use authentication") end disconnect