Exploiting Syntax Injection to Extract Data

Veröffentlicht am: 10 März 2025
auf dem Kanal: Intigriti
1,492
54

👩‍🎓👨‍🎓 Learn about NoSQL injection attacks! The user lookup functionality for this lab is powered by a MongoDB NoSQL database. It is vulnerable to NoSQL injection. To solve the lab, we'll extract the password for the administrator user, then log in to their account.

If you're struggling with the concepts covered in this lab, please review https://portswigger.net/web-security/... 🧠

🔗 ‪@PortSwiggerTV‬ challenge: https://portswigger.net/web-security/...

🧑💻 Sign up and start hacking right now - https://go.intigriti.com/register

👾 Join our Discord - https://go.intigriti.com/discord

🎙️ This show is hosted by   / _cryptocat   ( ‪@_CryptoCat‬ ) &   / intigriti  

👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com

Overview:
0:00 Intro
0:15 Exploiting syntax injection to extract data
0:36 Exfiltrating data in MongoDB
1:49 Lab: Exploiting NoSQL injection to extract data
2:07 Explore user lookup functionality
3:17 Test NOSQLi payloads
3:50 Automate data extraction with burp intruder (cluster bomb)
7:35 Conclusion


Auf dieser Seite können Sie das Online-Video Exploiting Syntax Injection to Extract Data mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer Intigriti 10 März 2025 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 1,492 Mal angesehen und es wurde von 54 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!