Scanning IPv4 for Free Data and Free Shells

No ratings

Presented at lascon 2016 by

In recent years, we've seen a huge increase in the number of available databases and key value stores such as Redis, MongoDB, Elasticsearch, Memcached, Cassandra, and more. Unfortunately, it is easy for users to set these products up in an insecure fashion, exposing them to everything from data theft to remote code execution. In this talk, we'll explore the results of scans covering the entire IPv4 space to determine the breadth of data exposed by these new database and key value stores, as well as measuring how many of these instances exposed to the Internet are vulnerable to exploitation.