MongoDB未授权访问漏洞
1、连接MongoDB,添加账号密码
mongo 127.0.0.1
use admin
db.createUser({
user: 'admin',
pwd: 'MongoDB123%.com',
roles:[{
role: 'root',
db: 'admin'
}]
})
创建admin用户,密码为:MongoDB123%.com
2、设置完成,可以通过指令 show users
查看是否设置成功
show users
{
"_id" : "admin.admin",
"userId" : UUID("4ea17f1a-53f1-481e-9021-6f3464c98ccf"),
"user" : "admin",
"db" : "admin",
"roles" : [
{
"role" : "root",
"db" : "admin"
}
],
"mechanisms" : [
"SCRAM-SHA-1",
"SCRAM-SHA-256"
]
}
3、认证方式
mongo 127.0.0.1/admin -u admin -p MongoDB123%.com