Exploiting Syntax Injection to Extract Data

Pubblicato il: 10 marzo 2025
sul canale di: Intigriti
1,492
54

👩‍🎓👨‍🎓 Learn about NoSQL injection attacks! The user lookup functionality for this lab is powered by a MongoDB NoSQL database. It is vulnerable to NoSQL injection. To solve the lab, we'll extract the password for the administrator user, then log in to their account.

If you're struggling with the concepts covered in this lab, please review https://portswigger.net/web-security/... 🧠

🔗 ‪@PortSwiggerTV‬ challenge: https://portswigger.net/web-security/...

🧑💻 Sign up and start hacking right now - https://go.intigriti.com/register

👾 Join our Discord - https://go.intigriti.com/discord

🎙️ This show is hosted by   / _cryptocat   ( ‪@_CryptoCat‬ ) &   / intigriti  

👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com

Overview:
0:00 Intro
0:15 Exploiting syntax injection to extract data
0:36 Exfiltrating data in MongoDB
1:49 Lab: Exploiting NoSQL injection to extract data
2:07 Explore user lookup functionality
3:17 Test NOSQLi payloads
3:50 Automate data extraction with burp intruder (cluster bomb)
7:35 Conclusion


In questa pagina del sito puoi guardare il video online Exploiting Syntax Injection to Extract Data della durata di ore minuti seconda in buona qualità , che l'utente ha caricato Intigriti 10 marzo 2025, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 1,492 volte e gli è piaciuto 54 spettatori. Buona visione!