akde/infosec

Information security is ultimately about managing risk


Enumeration

  • Try to just login. Per default, no user is required.
    mongodb $target
  • Enu­mer­ate with NSE scripts
    nmap -sV --script "mongo* and default" -p 27017 $target
  • Try to con­nect
    mongo 'mongodb://nodebb:nodebb@192.168.91.69:27017/nodebb'

Optional

  • Try https://github.com/codingo/NoSQLMap

Leave a Reply

About

Personal collection of some infosec stuff. Primary purpose of this site is to collect and organize for myself.

Note: Some content is not publicly visible due to copyright issues. Therefore, some links could be broken.

Checklists

Categories

Checklists: Ports

python -c 'import pty;pty.spawn("/bin/bash")';

python3 -c 'import pty;pty.spawn("/bin/bash")';