webPromedium
Mongo 2
spbctf
Task: MongoDB NoSQL injection in PHP 5.5.9 app where arrays are cast to strings. Solution: JSON string concatenation injection with duplicate key override and $where operator bypass.
$ ls tags/ techniques/
nosql_injection_ne_operatormongodb_query_operator_injectionjson_string_injectionduplicate_json_key_overridewhere_operator_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Mongo 1— web-kids20
- [web][Pro]Lab 329 — PipelineIQ — NoSQL Injection Authentication Bypass— hackadvisor
- [web][Pro]Lab 327 — PipelineIQ — NoSQL Injection Authentication Bypass— hackadvisor
- [web][Pro]Lab 326 — PulseBoard — NoSQL Injection in Authentication— hackadvisor
- [web][Pro]Pryzhok— hackerlab