531 B
531 B
NoSQL Injections
- No tables, but files (collections)
- Examples are Elasticsearch, MongoDB, Redis, CouchDB.
Querying
- Filter instead of SQL queries
- Redis docs
- MongoDB operators
- Elasticsearch docs
Tips & Tricks
- Pass HTTP parameter as an array instead of
user=
andpassword=
useuser[$operator]=foo
andpassword[$operator]=bar
- 2D array via
user[$nin][]=foo
- 2D array via