服務器又一次被惡意攻擊,MongoDB被刪庫

一臺裸奔在雲服務器上的MongoDB

前幾天在自己個人的一臺騰訊雲服務器上安裝了MongoDB,當時着急用,就用的默認配置,端口是默認端口,也沒設置密碼,還把bind_ip 設置成 0.0.0.0(允許所有ip遠程連接)😅,後來就把這事拋到腦後了,也因爲經常用無線網卡上網,ip經常是動態的,雲服務器的安全組就放開了所有的ip。

完全就是一臺裸奔在雲上的數據庫 😭 😭 😭

被攻擊

下午忙完工作,爲了方便學習,把MongoDB裏的幾條主要數據(json)都備份成.json文件了,然後就去喫飯。喫飯回來MongoDB客戶端連接失效,重連了一下MongoDB,建的庫不見了,留下了一個新庫:READ_ME_TO_RECOVER_YOUR_DATA,裏面只有一張表:README
在這裏插入圖片描述
不會被勒索了吧?還真是!數據庫全部內容如下:

All your data is a backed up. You must pay 0.015 BTC to 15QSUeLd23GnUQqqndbwWR5UaPPqnwpSrc 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: [email protected]

看MongoDB日誌,有個日本東京的IP【18.179.34.199】剛好在我喫飯這幾分鐘連接了數據庫:

2020-06-07T01:02:40.397+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54840 #23 (7 connections now open)
2020-06-07T01:02:40.547+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54842 #24 (8 connections now open)
2020-06-07T01:02:40.781+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54844 #25 (9 connections now open)
2020-06-07T01:02:41.118+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54856 #26 (10 connections now open)
2020-06-07T01:02:41.118+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54846 #27 (11 connections now open)
2020-06-07T01:02:41.121+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54848 #28 (12 connections now open)
2020-06-07T01:02:42.127+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54854 #29 (13 connections now open)
2020-06-07T01:02:42.129+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54852 #30 (14 connections now open)
2020-06-07T01:02:42.433+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54858 #31 (15 connections now open)
2020-06-07T01:02:44.147+0800 I NETWORK  [initandlisten] connection accepted from 18.179.34.199:54850 #32 (16 connections now open)
2020-06-07T01:03:21.051+0800 I NETWORK  [conn24] end connection 18.179.34.199:54842 (15 connections now open)
2020-06-07T01:03:21.058+0800 I NETWORK  [conn31] end connection 18.179.34.199:54858 (14 connections now open)
2020-06-07T01:03:21.058+0800 I NETWORK  [conn29] end connection 18.179.34.199:54854 (13 connections now open)
2020-06-07T01:03:21.058+0800 I NETWORK  [conn27] end connection 18.179.34.199:54846 (12 connections now open)
2020-06-07T01:03:21.058+0800 I NETWORK  [conn30] end connection 18.179.34.199:54852 (11 connections now open)
2020-06-07T01:03:21.060+0800 I NETWORK  [conn28] end connection 18.179.34.199:54848 (10 connections now open)
2020-06-07T01:03:21.060+0800 I NETWORK  [conn32] end connection 18.179.34.199:54850 (9 connections now open)
2020-06-07T01:03:21.345+0800 I NETWORK  [conn25] end connection 18.179.34.199:54844 (8 connections now open)
2020-06-07T01:03:21.347+0800 I NETWORK  [conn23] end connection 18.179.34.199:54840 (7 connections now open)
2020-06-07T01:03:21.633+0800 I NETWORK  [conn26] end connection 18.179.34.199:54856 (6 connections now open)

就喫頓飯的功夫~ 呵呵呵呵呵~ 😓 😓 😓 幸虧勞資備份了,讓黑客兄弟又少賺一千塊。

網上一看,中招的還有不少,留言的模板還都是一毛一樣的,被勒索的比特幣從0.005到1個以上的都有。

在羣裏吐槽也被運維兄弟噴了😭
在這裏插入圖片描述

安全事故猛於虎

幸虧這次丟失的數據不多,也只是自己個人的測試數據,如果是公司的商用數據庫數據,那被勒索多少BTC也得給啊 😁

這裏給再次給自己也給大家提個醒,安全事故猛於虎,安全責任重於山。

  • 一定不要爲了圖方便,就忽略某些安全配置,平時做什麼都要有安全意識。
  • 重要數據及時備份。
  • 服務器設置IP黑白名單,關閉一切可以關閉的端口
  • 如果跟我似的,訪問服務的ip經常變,可以考慮修改一些服務的默認端口,增加被掃到的概率
  • 一定要設置密碼,爲了防止被爆,最好是無規則的強密碼

在這裏插入圖片描述

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章