tylkomat
tylkomat
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
otherwise you have to learn how to secure a replica set
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
@rainTrip It may work if you don't expose the ports publicly.
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
I didn't spent time to learn how to configure replica sets. So I'm just not using them
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
You encountered the same issue that happened to me. Replica sets have to be configured and made secure by yourself. The slider that enables replica sets does only enable replica sets, but leaves everything unconfigured in terms of security. So I suspect the set is open for anyone to join and mess with your data
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
@rainTrip I disabled replica sets
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
@rainTrip I used MongoDB Compass with the credentials I provided when creating that database. I had to enable "Direct Connection" under "Advanced Connection Options" otherwise it wouldn't connect.
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
@Siumauricio I never used replica sets before, but that setting to enable makes it just too easy. It looks like replica sets are by default unprotected and if you make the mistake to open the container to the internet, than you are in big trouble. Probably it should at least ask for another set of credentials to be configured to protect the replica set. I would also suggest to configure a certificate when the database is opened to the internet. I wonder if many users use the database integration, since it lacks some options that a plain docker container has. Maybe special features are not even necessary for the predefined database integrations.
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
Thank you everyone for sharing your ideas
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
It was an accumulation of doing things differently and it exploded in the end 🙂
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
@Andres Ruiz I'm fine now. I was doing differently from how I usually do, since it was convenient. I managed now with keeping it private
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
I believe it was the combination of public port and replicaset. How the replicaset is configured by default in dokploy is not secure. It binds to all IPs, although it should only bind to the host IP. There are warnings everywhere in the mongo docs to secure everything before putting it public. I was expecting dokploy to handle this for me.
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
When I create a db via dokploy, I have to set a password, so yes
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
In the logs was no authentication entry other than from my IP
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
@hyteq Do you mean mongo connection details?
41 replies
DDokploy
Created by max.d on 9/17/2024 in #help
Certs for wildcard domains in traefik
I got it working. Thank you for your config
14 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
public key
41 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
I don't have a static ip
41 replies
DDokploy
Created by max.d on 9/17/2024 in #help
Certs for wildcard domains in traefik
The routing works, but there is no wildcard certificate generated. I set the corresponding Environment Variables for my DNS provider in the traefik environment. Do I have to set something else?
14 replies
DDokploy
Created by max.d on 9/17/2024 in #help
Certs for wildcard domains in traefik
@max.d
14 replies
DDokploy
Created by tylkomat on 1/6/2025 in #help
mongodb hacked after a view hours of being accessible
there was also 27017 in the same way, which I removed after the breach
41 replies