Advice Request MongoDB data security

Please provide comments and solutions that are helpful to the author of this topic.

Haldrik

New Member
Thread author
May 1, 2021
1
Hi everyone, this is my first post.

I run a few NodeJS/ExpressJS/PassportJS web apps housed on DigitalOcean droplets that have ssh key access only, and only one user on the host system (me). The MongoDB instances used by the apps and running on the same droplets are password protected and only accessible to localhost. In the apps themselves, there is only one admin account (also me), and my passwords (to admin account in the apps) are 12 character random strings.

With a setup like this, what are some of the greatest potential risks or entry points where someone could gain unauthorized access to the database?

Thanks for any tips!
 
  • Like
Reactions: Stopspying

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top