👩🎓👨🎓 Learn about NoSQL injection attacks! The user lookup functionality for this lab is powered by a MongoDB NoSQL database. It is vulnerable to NoSQL injection. To solve the lab, we'll extract the password for the administrator user, then log in to their account.
If you're struggling with the concepts covered in this lab, please review https://portswigger.net/web-security/... 🧠
🔗 @PortSwiggerTV challenge: https://portswigger.net/web-security/...
🧑💻 Sign up and start hacking right now - https://go.intigriti.com/register
👾 Join our Discord - https://go.intigriti.com/discord
🎙️ This show is hosted by / _cryptocat ( @_CryptoCat ) & / intigriti
👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com
Overview:
0:00 Intro
0:15 Exploiting syntax injection to extract data
0:36 Exfiltrating data in MongoDB
1:49 Lab: Exploiting NoSQL injection to extract data
2:07 Explore user lookup functionality
3:17 Test NOSQLi payloads
3:50 Automate data extraction with burp intruder (cluster bomb)
7:35 Conclusion
Auf dieser Seite können Sie das Online-Video Exploiting Syntax Injection to Extract Data mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer Intigriti 10 März 2025 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 1,492 Mal angesehen und es wurde von 54 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!