May 2017
Intermediate to advanced
416 pages
21h 33m
English
We launch the NSE script mongodb-databases if a MongoDB server is found running on port 27017 (-p 27017 --script mongodb-databases). By default, MongoDB does not have authentication enabled. If the administrators haven't configured users and roles, the databases will be accessible to anyone.
The script mongodb-brute was submitted by Patrik Karlsson, and it can be used to perform brute force password authentication against MongoDB instances. The script is also capable of detecting instances that do not have authentication enabled.
Read now
Unlock full access