That we should not forget the value of cybersecurity.
The notorious ‘meow' attacks wiped almost , including those of Elasticsearch and MongoDB. Threat actors targeted unsecured databases and destroyed all of their data.
What we have learned from these and other attacks is that in order to stay vigilant and proactive (especially if you easily miss telltale ‘meow signatures’ on server files) you should consider these easy steps:
1. Start small by creating separate security credentials for each user when you need to grant administrative access to the database.
2. Safeguard and consolidate your noble endeavors by limiting connections to the database, i.e. whitelisting.
Once you tick this box, go over to encrypting network traffic. The data doesn’t transport to your database with a magic wand. Typically, it goes through a network connection. That’s when encryption comes into play.
3. Make sure that you implement auditing.
4. Finally, do not stick with default settings! This is a recipe for disaster.
Important Disclaimer: No cats were harmed during the production of this newsletter. We love cats too and hope all they all are safe in this stressful time.
Subscribe to HackerNoon’s thematic newsletters via our subscribe form in the footer.
Click Here to Sponsor A Newsletter by Hacker Noon