Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Simply set a secure password on any DB instances exposed to the internet.


Ah, I see. So no need to find a static IP to use :) Thank you.


I mean, if the database is not directly available on the internet, that would be a great help as well.


Agreed, password is the bare minimum.


Are the databases being meowed lacking any passwords?


At least in the case of MongoDB, yes. Listening on all interfaces and not having a password set.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: