Hunt Open MongoDB instances!
- Worlds fastest and most efficient scanner ( Uses Masscan ).
- Scans entire internet by default, So fire the tool and chill.
- Hyper efficient - Uses Go-routines which are even lighter than threads.
- Go language ( sudo apt install golang )
- Masscan ( sudo apt install masscan )
- Tested on Ubuntu & Kali linux
How to install and run -
git clone https://github.com/yashpl/mongoBuster.gitNote: Run it with sudo as Masscan requires sudo access.
go build mongobuster.go utils.go
|--max-rate= (int)||Defines maximum rate at which packets are generated and sent. Default is 100.|
|--out-file= (string)||Name of file to which vulnerable IPs will be exported.|
|-v||Display error msgs from non-vulnerable servers|
Using ridiculous values for
max-rateflag like 10000+ will most likely bring down your own network infrastructure.
Recommended value is to start with
--max-rate 500for consumer Gigabit routers.