mongod binds all network interfaces and accepts all request without any auth on port 27017 and 28017.
It means anyone can access mongod from worldwide. I think it's a little bit danger default setting.
Is it possible to binds only localhost by default?
- related to
-
SERVER-4216 [SECURITY] mongodb 10gen debian package listens on all interfaces by default
- Closed