自查方法:
黑客在被勒索的数据库内遗留勒索信息,如果您发现以下特征,表示已被入侵:
1.数据库内被创建了“Wanrning”的数据库,并创建了"Readme"表;
2."Readme"表内的勒索留言内容:
{ "_id" : { "$oid" : "5a19985144e90e0224ecb5f8" },
"BitCoin" : "1EPA6qXtthvmp5kU82q8zTNkFfvUknsShS",
"eMail" : "cru3lty@safe-mail.net",
"Exchange" : "https://localbitcoins.com",
"Solution" : "Your DataBase is downloaded and backed up on our secured servers. To recover your lost data: Send 0.2 BTC to our BitCoin Address and Contact us by eMail with your MongoDB server IP Address and a Proof of Payment. Any eMail without your MongoDB server IP Address and a Proof of Payment together will be ignored. You are welcome!" }