How hackers search and hijack sensitive databases?

This will be an exciting blog!

Today we will try to show how easily cyber attackers can gain access to sensitive database. Let’s start.


There are two ways to find test subjects.

The first way is take help of existing online services that scan the whole internet and provide us with information.


We will not show everything in detail, but will help you with a few interesting examples. Here is a MongoDB search query for the Fofa service.

A similar service is A request to search for hosts with CouchDB raised here.

A second way is to use advanced scanners.

  1. Nmap
  2. Masscan
  3. Zmap from the utility package
  4. Sonar project
  5. Something of its own

Scanning is, of course, manual, but why not use a ready-made dataset? For example, if your VPS provider does not allow you to scan everything at high speed, then these guys have already done everything for you. Almost!

Not many people have heard of Project Sonar. It is a research project that scans services and protocols to gain insight into the global impact of common vulnerabilities. Developed by the company that created the Metasploit Framework. Hopefully, you know about — Rapid7. The collected data is available to the general public for security research.

For Masscan, write the following command to start:

masscan -p9200,9042,5984,27017

that we have a list of hosts in hand, we can proceed to a detailed check.

