DocumentDB is AWS's MongoDB-compatible database. It has no IAM data plane: access is the cluster endpoint plus a database username and password, so it falls to the same exposure pattern as self-hosted Mongo. Credentials typically live in Secrets Manager or an application's config, and a cluster reachable from a compromised VPC host is one credential away from a full read.
Finding and connecting#
aws docdb describe-db-clusters \
--query 'DBClusters[].[DBClusterIdentifier,Endpoint,Port]'
# connect with the mongo shell (TLS on by default)
mongosh "mongodb://<user>:<pw>@<endpoint>:27017/?tls=true&tlsCAFile=global-bundle.pem"
Exploitation notes#
- DocumentDB is almost always inside a VPC, so this is a post-foothold technique reached from an EC2 box or through a pivot, not from the internet.
- Credentials recovered from Secrets Manager or an app server are the usual key; the database itself has no second factor.
- Dump collections with
mongodumponce connected for offline analysis.
Tools#
- AWS CLI (
docdb describe-db-clusters). - mongosh / mongodump: native MongoDB clients.