mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-26 14:10:59 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
# Standards & References — NoSQL Injection
|
||||
|
||||
## Industry Standards
|
||||
- **OWASP Top 10 2021 A03** — Injection (includes NoSQL injection)
|
||||
- **OWASP Testing Guide** — Testing for NoSQL Injection (WSTG-INPV-05.6)
|
||||
- **CWE-943** — Improper Neutralization of Special Elements in Data Query Logic
|
||||
- **MITRE ATT&CK T1190** — Exploit Public-Facing Application
|
||||
|
||||
## Technical References
|
||||
- PortSwigger Web Security Academy: https://portswigger.net/web-security/nosql-injection
|
||||
- OWASP NoSQL Testing Guide: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/05.6-Testing_for_NoSQL_Injection
|
||||
- PayloadsAllTheThings NoSQL: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection
|
||||
- MongoDB Security Checklist: https://www.mongodb.com/docs/manual/administration/security-checklist/
|
||||
- HackTricks NoSQL: https://book.hacktricks.xyz/pentesting-web/nosql-injection
|
||||
|
||||
## Tools
|
||||
- NoSQLMap: https://github.com/codingo/NoSQLMap
|
||||
- nosqli: https://github.com/Charlie-belmer/nosqli
|
||||
- MongoDB documentation on query operators: https://www.mongodb.com/docs/manual/reference/operator/query/
|
||||
@@ -0,0 +1,23 @@
|
||||
# Workflows — NoSQL Injection Exploitation
|
||||
|
||||
## Detection Workflow
|
||||
1. Identify application technology stack (check for MongoDB, CouchDB indicators)
|
||||
2. Map all input points accepting JSON data or query parameters
|
||||
3. Submit operator payloads ($ne, $gt, $regex) in each parameter
|
||||
4. Monitor responses for authentication bypass or data leakage
|
||||
5. Test for JavaScript injection via $where operator
|
||||
6. Document all vulnerable endpoints with proof-of-concept payloads
|
||||
|
||||
## Blind Extraction Workflow
|
||||
1. Confirm boolean-based injection by comparing true/false responses
|
||||
2. Determine password/field length using $regex with length patterns
|
||||
3. Extract characters one at a time using $regex "^<known_chars><test>"
|
||||
4. Automate extraction with Python script using binary search
|
||||
5. Validate extracted data by attempting authentication
|
||||
|
||||
## Automated Scanning Workflow
|
||||
1. Configure proxy (Burp Suite) to intercept target traffic
|
||||
2. Run NoSQLMap against identified endpoints
|
||||
3. Use nuclei with NoSQL injection templates for broad coverage
|
||||
4. Manually verify automated findings with crafted payloads
|
||||
5. Escalate confirmed findings to data extraction or RCE attempts
|
||||
Reference in New Issue
Block a user