MongoDB is currently open without authentication.
This results in all the database data made available publicly.
Severity: medium
Fingerprint: 436d217a47ab4258408c64468ca16d085c381722ca7564e00b4b873763d4cb9e
Collections: 5, document count: 8, size: 3.3 kB HTTP/1.0 200 OK Connection: close Content-Type: text/plain Content-Length: 85 It looks like you are trying to access MongoDB over HTTP on the native driver port. Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (375 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.system.version with 2 documents (104 B) Found collection admin.GODRANSOM with 1 documents (621 B) Found collection config.system.sessions with 0 documents (0 B)
Severity: high
Fingerprint: 436d217a47ab42583a37d0a1cc2111099fe4cedd7e04d6606199cfc8986841ec
Collections: 5, document count: 15, size: 3.4 kB Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 1 documents (739 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.test with 7 documents (259 B) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 1 documents (99 B)
Severity: high
Fingerprint: 436d217a47ab42589452e24854460b29efaf7efdce69f5002e6927e8a9142279
Collections: 5, document count: 15, size: 4.0 kB Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 2 documents (1.5 kB) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.test with 7 documents (259 B) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 0 documents (0 B)
Severity: medium
Fingerprint: 436d217a47ab425857c8cf51e84874b570449e610c7a010c7512a41ca18e96dd
Collections: 5, document count: 14, size: 3.3 kB Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (745 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.test with 7 documents (259 B) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 0 documents (0 B)
Severity: medium
Fingerprint: 436d217a47ab4258b368476f43902ce8087b2dd4f3415a240333220503332205
Collections: 4, document count: 7, size: 3.0 kB Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (744 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 0 documents (0 B)
Severity: medium
Fingerprint: 436d217a47ab4258b368476f3cbef2e2b0f64d66381215b672014f9772014f97
Collections: 4, document count: 7, size: 3.0 kB Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (746 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 0 documents (0 B)
Severity: medium
Fingerprint: 436d217a47ab4258b368476f3cbef2e2b0f64d66381215b664d71e0e64d71e0e
Collections: 4, document count: 7, size: 3.0 kB Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (746 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions
Severity: medium
Fingerprint: 436d217a47ab4258b368476fc410c4b0bf987efcffa63c2c9a5bbcad9a5bbcad
Collections: 4, document count: 7, size: 3.0 kB Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (739 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 0 documents (0 B)
Fingerprint: 436d217a47ab4258c72de5545b094f2abc50d62630cf7b5e30cf7b5e30cf7b5e
Collections: 3, document count: 1, size: 738 B Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (738 B) Found collection admin.system.users Found collection admin.system.version
Fingerprint: 436d217a47ab4258b368476f852a11672860489bf58685550c8511ce0c8511ce
Collections: 4, document count: 7, size: 3.0 kB Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (738 B) Found collection admin.system.users with 4 documents (2.2 kB) Found collection admin.system.version with 2 documents (104 B) Found collection config.system.sessions with 0 documents (0 B)
Elasticsearch and/or Kibana is currently open without authentication.
This results in all the database data made available publicly.
Severity: high
Fingerprint: 831cb76b8e05df461f27c56366893d03d84963aa78d3139c78d3139c78d3139c
Indices: 3, document count: 2, size: 24.5 kB Found index casa with 0 documents (283 B) Found index read_me with 1 documents (4.5 kB) Found index service with 1 documents (19.6 kB)
Severity: high
Fingerprint: 831cb76b8e05df463b8f0edcca6e95f24f13754d4f13754d4f13754d4f13754d
Indices: 2, document count: 1, size: 4.8 kB Found index casa with 0 documents (283 B) Found index read_me with 1 documents (4.5 kB)
Severity: high
Fingerprint: 831cb76b8e05df4640f0fac6c20d1751c20d1751c20d1751c20d1751c20d1751
Indices: 1, document count: 1, size: 4.5 kB Found index read_me with 1 documents (4.5 kB)
Severity: high
Fingerprint: 831cb76b8e05df46b5ef1625ccd7b6f987ce9cf637d4eee927cb6a2510c43c24
Indices: 7, document count: 2055, size: 2.1 MB Found index read-me-hacked-by-nightlionsecurity-csw5ok with 1 documents (5.2 kB) Found index magento2_product_1_v4 with 2048 documents (2.1 MB) Found index read-me-hacked-by-nightlionsecurity-mykbpf with 1 documents (5.2 kB) Found index api with 2 documents (9.1 kB) Found index read-me-hacked-by-nightlionsecurity-qlyyf0 with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-ewbepd with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-mwnfvc with 1 documents (5.2 kB)
Severity: high
Fingerprint: 831cb76b8e05df46b5ef1625ccd7b6f9b354a56ee2b3f04510cdb0f92e2cba68
Indices: 7, document count: 2055, size: 2.1 MB Found index read-me-hacked-by-nightlionsecurity-csw5ok with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-mykbpf with 1 documents (5.2 kB) Found index magento2_product_1_v4 with 2048 documents (2.1 MB) Found index api with 2 documents (9.1 kB) Found index read-me-hacked-by-nightlionsecurity-qlyyf0 with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-ewbepd with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-mwnfvc with 1 documents (5.2 kB)
Severity: high
Fingerprint: 831cb76b8e05df46b5ef1625ccd7b6f9b354a56ee2b3f0451f0eab2e10de19b2
Indices: 7, document count: 2055, size: 2.1 MB Found index read-me-hacked-by-nightlionsecurity-csw5ok with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-mykbpf with 1 documents (5.2 kB) Found index magento2_product_1_v4 with 2048 documents (2.1 MB) Found index read-me-hacked-by-nightlionsecurity-qlyyf0 with 1 documents (5.2 kB) Found index api with 2 documents (9.1 kB) Found index read-me-hacked-by-nightlionsecurity-ewbepd with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-mwnfvc with 1 documents (5.2 kB)
Severity: high
Fingerprint: 831cb76b8e05df46f4abe822d82517fe2505ab3561b282721f6c3e3194713cbf
Indices: 6, document count: 2053, size: 2.1 MB Found index read-me-hacked-by-nightlionsecurity-csw5ok with 1 documents (5.2 kB) Found index magento2_product_1_v4 with 2048 documents (2.1 MB) Found index read-me-hacked-by-nightlionsecurity-mykbpf with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-qlyyf0 with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-ewbepd with 1 documents (5.2 kB) Found index read-me-hacked-by-nightlionsecurity-mwnfvc with 1 documents (5.2 kB)
Severity: high
Fingerprint: 831cb76b8e05df463687ff1ec67242549cca88c29cca88c29cca88c29cca88c2
Indices: 2, document count: 2, size: 10.0 kB Found index read__me with 1 documents (4.9 kB) Found index api with 1 documents (5.0 kB)
Fingerprint: 831cb76b8e05df463d8116520536840005368400053684000536840005368400
Indices: 1, document count: 1, size: 4.9 kB Found index read__me with 1 documents (4.9 kB)
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e366433e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git://github.com/mobz/elasticsearch-head.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master