frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MongoBleed

https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py
44•gpi•5h ago

Comments

dpark•2h ago
Do people usually run Mongo in a mode that allows unauthenticated calls? I don’t know anything about Mongo. This just seems surprising.
giancarlostoro•2h ago
Its default is to only take connections that are local, usually I have my mongo clients SSH into a mongo server as opposed to opening up the port to the internet. Some Mongo users / collections are very open by default.

It has been a minute since I used Mongo for production grade projects, so some things could have changed since then.

erdaniels•1h ago
No, but it's pretty common IME to create an Atlas cluster that has internet-wide access (0.0.0.0/0) when testing and forgetting to turn this off. According to https://jira.mongodb.org/browse/SERVER-115508, this affects unauthenticated ops. Based on the repro code itself, it looks like this happens way before authentication is checked for the corresponding OP at the OP_MSG decoding level.

So if you're using Atlas, check that your Cluster has auto upgraded already. If you're using 0.0.0.0/0, stop doing that and prefer a limited IP address range and even better, use VPC Peering or other security/network boundary features.

computerfan494•1h ago
We received communication that all Atlas clusters were upgraded with the fix before the vulnerability was announced.
FridgeSeal•1h ago
Current link points straight to the Python code without a lot of context, so here’s the top of the readme:

> CVE-2025-14847 - MongoDB Unauthenticated Memory Leak Exploit

> A proof-of-concept exploit for the MongoDB zlib decompression vulnerability that allows unauthenticated attackers to leak sensitive server memory.

winrid•12m ago
Luckily most people wouldn't use zlib anyway, they'd use snappy or zstd, and this also requires authenticated access to the cluster ....

How uv got so fast

https://nesbitt.io/2025/12/26/how-uv-got-so-fast.html
417•zdw•6h ago•144 comments

Experts explore new mushroom which causes fairytale-like hallucinations

https://nhmu.utah.edu/articles/experts-explore-new-mushroom-which-causes-fairytale-hallucinations
256•astronads•6h ago•116 comments

The Best Things and Stuff of 2025

https://blog.fogus.me/2025/12/23/the-best-things-and-stuff-of-2025.html
48•adityaathalye•3d ago•5 comments

How Lewis Carroll computed determinants (2023)

https://www.johndcook.com/blog/2023/07/10/lewis-carroll-determinants/
126•tzury•4h ago•23 comments

Drawing with zero-width characters

https://zw.swerdlow.dev
43•benswerd•4h ago•18 comments

-tucky

https://languagelog.ldc.upenn.edu/nll/?p=58650
10•benatkin•2d ago•1 comments

My insulin pump controller uses the Linux kernel. It also violates the GPL

https://old.reddit.com/r/linux/comments/1puojsr/the_device_that_controls_my_insulin_pump_uses_the/
255•davisr•4h ago•88 comments

Package managers keep using Git as a database, it never works out

https://nesbitt.io/2025/12/24/package-managers-keep-using-git-as-a-database.html
543•birdculture•10h ago•315 comments

Show HN: Witr – Explain why a process is running on your Linux system

https://github.com/pranshuparmar/witr
146•pranshuparmar•8h ago•19 comments

Gaussian Splatting 3 Ways

https://github.com/NullandKale/NullSplats
38•nullandkale•4h ago•3 comments

LearnixOS

https://www.learnix-os.com
186•gtirloni•10h ago•66 comments

Parasites plagued Roman soldiers at Hadrian's Wall

https://arstechnica.com/science/2025/12/study-roman-soldiers-battled-parasites-at-hadrians-wall/
27•sipofwater•1w ago•15 comments

FFmpeg has issued a DMCA takedown on GitHub

https://twitter.com/FFmpeg/status/2004599109559496984
338•merlindru•5h ago•84 comments

Perfect Aircrete, Kitchen Ingredients [video]

https://www.youtube.com/watch?v=z4_GxPHwqkA
62•surprisetalk•6d ago•21 comments

Migrating my web analytics from Matomo to Umami

https://stanislas.blog/2025/12/migrating-matomo-to-umami-web-analytics/
28•angristan•2d ago•2 comments

MongoBleed

https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py
44•gpi•5h ago•6 comments

Ask HN: What did you read in 2025?

125•kwar13•10h ago•162 comments

How I think about Kubernetes

https://garnaudov.com/writings/how-i-think-about-kubernetes/
53•todsacerdoti•2h ago•33 comments

Show HN: Xcc700: Self-hosting mini C compiler for ESP32 (Xtensa) in 700 lines

https://github.com/valdanylchuk/xcc700
78•isitcontent•8h ago•16 comments

Unix "find" expressions compiled to bytecode

https://nullprogram.com/blog/2025/12/23/
94•rcarmo•11h ago•12 comments

Grok and the Naked King: The Ultimate Argument Against AI Alignment

https://ibrahimcesar.cloud/blog/grok-and-the-naked-king/
23•ibrahimcesar•4h ago•10 comments

Sandbox: Run untrusted AI code safely, fast

https://github.com/PwnFunction/sandbox
46•vortex_ape•1w ago•12 comments

Rob Pike goes nuclear over GenAI

https://skyview.social/?url=https%3A%2F%2Fbsky.app%2Fprofile%2Frobpike.io%2Fpost%2F3matwg6w3ic2s&...
1122•christoph-heiss•9h ago•1427 comments

The Algebra of Loans in Rust

https://nadrieril.github.io/blog/2025/12/21/the-algebra-of-loans-in-rust.html
179•g0xA52A2A•4d ago•84 comments

A Proclamation Regarding the Restoration of the Dash

https://blog.nawaz.org/posts/2025/Dec/a-proclamation-regarding-the-restoration-of-the-dash/
98•BeetleB•6h ago•103 comments

What happened to all the gold Spain got from the New World? (1985)

https://www.straightdope.com/21341789/what-happened-to-all-the-gold-spain-got-from-the-new-world
59•titaniumtown•4d ago•96 comments

Show HN: AutoLISP interpreter in Rust/WASM – a CAD workflow invented 33 yrs ago

https://acadlisp.de/noscript.html
100•holg•7h ago•30 comments

ZJIT is now available in Ruby 4.0

https://railsatscale.com/2025-12-24-launch-zjit/
75•ibobev•6h ago•24 comments

Joan Didion and Kurt Vonnegut had something to say. We have it on tape

https://www.nytimes.com/2025/12/19/books/james-baldwin-joan-didion-92ny-recordings.html
88•tintinnabula•4d ago•19 comments

C/C++ Embedded Files (2013)

https://www.4rknova.com//blog/2013/01/27/cpp-embedded-files
40•ibobev•6h ago•36 comments