webProeasy

Lab 328 — DataNest — NoSQL Operator Injection in Authentication

hackadvisor

Task: Analytics dashboard with role-based access control, login accepts JSON. Solution: NoSQL operator injection using $ne operator to bypass password authentication and access admin settings.

$ ls tags/ techniques/
nosql_injection_ne_operatormongodb_query_operator_injectionjson_content_type_injectionteam_page_enumeration

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups