mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-06-11 21:54:56 +03:00
1.1 KiB
1.1 KiB
Workflows — NoSQL Injection Exploitation
Detection Workflow
- Identify application technology stack (check for MongoDB, CouchDB indicators)
- Map all input points accepting JSON data or query parameters
- Submit operator payloads ($ne, $gt, $regex) in each parameter
- Monitor responses for authentication bypass or data leakage
- Test for JavaScript injection via $where operator
- Document all vulnerable endpoints with proof-of-concept payloads
Blind Extraction Workflow
- Confirm boolean-based injection by comparing true/false responses
- Determine password/field length using $regex with length patterns
- Extract characters one at a time using $regex "^<known_chars>"
- Automate extraction with Python script using binary search
- Validate extracted data by attempting authentication
Automated Scanning Workflow
- Configure proxy (Burp Suite) to intercept target traffic
- Run NoSQLMap against identified endpoints
- Use nuclei with NoSQL injection templates for broad coverage
- Manually verify automated findings with crafted payloads
- Escalate confirmed findings to data extraction or RCE attempts