Kanganiso yekumisikidza muMongoDB yakapa mukana kune database

Kushatirwa

Muvhuro wekupedzisira Bob Diachenko akatumira nezve zvaakawana nezve kufumura data kubva kungopfuura mamirioni gumi nemana marekodhi yevanhu mune zvakawanikwa zvemunhu izvi.

Dhatabhesi hombe yemamirioni gumi nemamiriyoni emaimeri akanyorwa. Iko kuwanikwa kwakaitika neMuvhuro uye izvo zvese zvinoratidza, dhatabhesi rakanga rizere neruzivo rwemunhu kuwedzera kumaemail.

Dambudziko

The data chii chavakaitwa akachengetwa mune yeMongoDB semuenzaniso uye akagashirwa mune yeSMS-SMS, LLC fomati uyezve, idzi data dzinogona kuwanikwa nechero ani kuti aiziva kushandisa maturusi chaiwo.

Bob Diachenko, anova mumwe wevanonyanya kuremekedzwa vezvekuchengetedza, akakwanisa kuwana ruzivo rwakadai painternet vachishandisa maturusi eruzhinji.

Paunenge uchitsvaga, Bob akaona kuti ruzivo urwu rwakanga ruchinyorerwa neiyo Shodan yekutsvaga injini. uye kuti yekupedzisira kugadziridza kwakaitika munaGunyana 13, zvisinei, akatadza kuziva mamwe mazuva pamberi pekuti Shodan akwanise kunongedza zvirimo uye nekudaro kuzviita, veruzhinji.

Iyo diki faira yeiyo 43,5 GB chete iyo ine ingangoita gumi nemakumi mapfumbamwe nemakumi mapfumbamwe nemapfumbamwe nemakumi mashanu nemashanu emakero uye yese yeYahoo, iinewo rekutanga uye rekupedzisira zita, kero, zip kodhi, nyika uye guta.

Ruzivo irwo mudhatabhesi (maemail ane ruzivo rwevanhu) yaive goridhe chaiyo yemhando dzese dzevanhu vanovashandisa zvinangwa zvakashata senge spammers, scammers, phishers emarudzi ese.

 

Kuziva nyika neguta, vazhinji vanofanirwa kunge vakashandisa dhata rakadai kushandisa mukuita kwavo spammers, scammers, botnet, malware senge rudzikunuro, spyware uye zvimwe zvakawanda zvinokuvadza maitiro, uye njodzi yekuve nevakawanda vakaurayiwa zvirokwazvo yakakwira, nekuda kwe assertiveness vashandisi 'pachedu data.

Iyo dhatabhesi iyo yakakanganiswa yakaongororwa uye zvinoenderana nezvakaonekwa, zvese ndezve SaverSpy, Asi haisi SaverSpy chete inoshandisa dhatabhesi iyi, saiti senge cupons.com nemamwe mapurogiramu akabatana anopa pasi rose, anogona kunge achigovana dhatabhesi iyi.

Kukanganisa kwevanhu

Iyo sevha inoita kunge iri yekambani yeCalifornia-based email yekutengesa. Parizvino, iyo kambani inomirira iyo data haina kuda kutaura chaizvo makambani ari vashandisi veiyi hombe dhatabhesi.

Kupfuura zvese, nerombo rakanaka hapana bhangi kana kiredhiti kadhi ruzivo runowoneka mukudonha uku.

zvinoshamisa MongoDB iri mubvunzo yatove yakamakwa se'Compromised 'muShodan uye zvirimo iyo 'Yambiro' dhatabhesi neiyo 'Readme' muunganidzwa uye tsamba yekudzikinura inoda 0.4 BTC kudzorera data iyo yaive iine muunganidzwa wedatha nerunotevera rugwaro:

»Dhatabhesi yako inotorwa pasi uye inotsigirwa pamaseva edu akachengeteka. Kuti uwanezve yako yakarasika data: tumira 0.4 BTC kukero yeBitCoin uye utitane nesu neemail ine server IP kero uye humbowo hwekubhadhara.

Chero chero email isina yako IP kero uye humbowo hwekubhadhara hauzofuratirwe. Iwe unogona kukumbira pfupiso yekuchengetedza mukati maawa gumi nemaviri.

Ipapo tichabvisa iyo backup. Hapana dambudziko! «

Zvisinei, panguva yekuwanikwa, data rese raive rakamira. Ndiri kufungidzira izvi mhedzisiro yekundikana kuyedza kunoshandiswa nemakoronyera (uye nerombo rakanaka kune varidzi ve database).

Iye zvino, dhatabhesi ratove roga uye mumazuva mashoma anotevera injini yekutsvaga yakanongedza ruzivo ichazofanira kudzima data.

Mukuwedzera kune ruzivo rwemunhu wevatengi, dhatabhesi iyi yaisanganisirawo ruzivo rweDNS nezve mamiriro eemail (akatumirwa zvinobudirira kana kuti kwete), zvichiratidza kana iyo email yakagadziriswa uye mhinduro kubva kuseva.

Iwe unogona kuona ruzivo nezve zvakabatana zvirongwa zvinogona kuverengerwa mudhatabhesi kana kushomeka kwekuwana kune dhatabhesi rakaburitswa nemuongorori.


Izvo zviri muchinyorwa zvinoomerera pamisimboti yedu ye tsika dzekunyora. Kuti utaure chikanganiso tinya pano.

Iva wekutanga kutaura

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa.

*

*

  1. Inotarisira data: AB Internet Networks 2008 SL
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako