How to find NoSQL Injection

  Рет қаралды 9,213

Ryan John

Ryan John

Күн бұрын

Пікірлер: 20
@LEOSTRIBE
@LEOSTRIBE Жыл бұрын
can you provide all the extensions which are use by you ?
@MsTitoxp
@MsTitoxp Жыл бұрын
Thank you Ryan!
@silenthacker2667
@silenthacker2667 Жыл бұрын
You always make over power video..i am from India love you sir❤❤
@karrivenkatesh1277
@karrivenkatesh1277 Жыл бұрын
Sir can ypi make a video series of CEH certified ethical hacking course
@kennethnwaigwe1213
@kennethnwaigwe1213 Жыл бұрын
And pls can you create a video about web app firewall...IDS..and IP bypass tutorials
@KellyFundz-zt3er
@KellyFundz-zt3er 6 ай бұрын
I have did all the injections and it's get a 200 ok status code but no interest output
@kennethnwaigwe1213
@kennethnwaigwe1213 Жыл бұрын
Great video...💯Pls do you reply to emails...cos I might actually be having a lot of questions that I cant...remember now...???
@KellyFundz-zt3er
@KellyFundz-zt3er 6 ай бұрын
Hi how sorry to bother you but I'm having a nosql injection on the parameter Referer
@praveenja3073
@praveenja3073 Жыл бұрын
Bug bounty tips need sir from India
@ryan_phdsec
@ryan_phdsec Жыл бұрын
I will do this next
@iqyou-gw4kd
@iqyou-gw4kd Жыл бұрын
what is nosql inection
@ryan_phdsec
@ryan_phdsec Жыл бұрын
They are the newer types of databases that stores data in a non-relational tables. I think they will fade out eventually, but I could be wrong. Most large companies will use some kind of sql database because they are dependable. Small new companies are more likely to use nosql
@iqyou-gw4kd
@iqyou-gw4kd Жыл бұрын
@@ryan_phdsec thank you sir plz explain null bayte injection. And add subtitles Arabic if you can and thank you
@the-avid-engineer
@the-avid-engineer Жыл бұрын
I seriously doubt this is a MongoDb injection attack. MongoDb queries do not use `||` to represent “or”, nor "=" to represent equality. MongoDb queries have a JSON-like structure, and an “or” query would be of the form “{$or:[,]}", and an equality criteria would be of the form {"":""} You cannot trick MongoDb with {"username":"admin || 1=1"}
@ceciliahkuriah927
@ceciliahkuriah927 7 ай бұрын
You can use attack a mongodb with either a syntax injection or an operator injection. in his case he used syntax injection. In your case you are using an operator injection. if the application is parsing data input in JSON then try using operator injection.
@the-avid-engineer
@the-avid-engineer 6 ай бұрын
⁠​⁠@@ceciliahkuriah927 In my case it isn’t an injection - it’s just looking for username equal to `admin || 1=1` which won’t do anything special or unexpected. In the other case, it cannot be attacking mongo because mongo does not have native support for SQL-like syntax. If this application is using SQL-like syntax to talk to mongo, then there must be some non-mongo layer translating the query from SQL-like to mongo-like, and the attack is against that layer, not mongo itself.
@firosiam7786
@firosiam7786 Жыл бұрын
No sql sql jwt etc etc etc too much info how do u learn all these and remember every techniques like this world of hacking is too large
@ryan_phdsec
@ryan_phdsec Жыл бұрын
Just time i think. Also take good notes... I have notes for everything.
@KingArnold-b1j
@KingArnold-b1j Ай бұрын
show off
NoSQL Injection Tutorial For Beginners
9:45
Loi Liang Yang
Рет қаралды 35 М.
Find and Exploit NoSQL Injection
11:03
The Cyber Mentor
Рет қаралды 18 М.
Hilarious FAKE TONGUE Prank by WEDNESDAY😏🖤
0:39
La La Life Shorts
Рет қаралды 44 МЛН
УНО Реверс в Амонг Ас : игра на выбывание
0:19
Фани Хани
Рет қаралды 1,3 МЛН
"Идеальное" преступление
0:39
Кик Брейнс
Рет қаралды 1,4 МЛН
How Learning Works | For Hacking
8:00
Ryan John
Рет қаралды 10 М.
SQL injection for Bug Bounty | POC | Report
10:37
Ryan John
Рет қаралды 12 М.
NoSQL INJECTION FOR BEGINNERS!
8:46
Farah Hawa
Рет қаралды 21 М.
How SQL injection Works | Bug Bounty | Ethical Hacking
4:45
Ryan John
Рет қаралды 7 М.
SQL Injection Attack Tutorial - I didn't know you can do that
12:59
Loi Liang Yang
Рет қаралды 42 М.
Easiest Vulnerabilities  in Bug Bounty
4:16
Ryan John
Рет қаралды 11 М.
Hacker Tools - NoSQLMap
7:08
Intigriti
Рет қаралды 7 М.
Find Information from a Phone Number Using OSINT Tools [Tutorial]
16:59
Hilarious FAKE TONGUE Prank by WEDNESDAY😏🖤
0:39
La La Life Shorts
Рет қаралды 44 МЛН