<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nosqli Archives - Tech Chronicles</title>
	<atom:link href="http://kostacipo.stream/tag/nosqli/feed/" rel="self" type="application/rss+xml" />
	<link>http://kostacipo.stream/tag/nosqli/</link>
	<description>Ramblings of a Tech Dude</description>
	<lastBuildDate>Wed, 11 Nov 2020 20:38:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>https://kostacipo.stream/wp-content/uploads/2019/12/cropped-profile-32x32.jpg</url>
	<title>nosqli Archives - Tech Chronicles</title>
	<link>http://kostacipo.stream/tag/nosqli/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>NoSQLi &#8211; A Fast NoSQL Injection Scanner</title>
		<link>http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/</link>
					<comments>http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Wed, 11 Nov 2020 20:38:21 +0000</pubDate>
				<category><![CDATA[Data]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Vulnerability Analysis]]></category>
		<category><![CDATA[data analysis]]></category>
		<category><![CDATA[nosqli]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1879</guid>

					<description><![CDATA[<p>&#160; nosqli was developed as an open source NoSQL scanner written in Go. It&#8217;s configurable with command line options, and runs a large number of injection attempts against targets. It&#8217;s mostly focused on Mongo injections, but does work to a lesser extent against any database that uses JavaScript. $ nosqli NoSQLInjector is a CLI tool [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/">NoSQLi &#8211; A Fast NoSQL Injection Scanner</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<header class="post-header">
<div class="post-header-wrap">&nbsp;</div>
</header>
<section class="post-wrapper">
<section class="post-content"><a href="https://github.com/Charlie-belmer/nosqli">nosqli</a> was developed as an open source NoSQL scanner written in Go. It&#8217;s configurable with command line options, and runs a large number of injection attempts against targets. It&#8217;s mostly focused on Mongo injections, but does work to a lesser extent against any database that uses JavaScript.</p>
<pre class=" language-bash"><code class=" language-bash">$ nosqli
NoSQLInjector is a CLI tool <span class="token keyword">for</span> testing Datastores that 
<span class="token keyword">do</span> not depend on SQL as a query language. 

nosqli aims to be a simple automation tool <span class="token keyword">for</span> identifying and exploiting 
NoSQL Injection vectors.

Usage:
  nosqli <span class="token punctuation">[</span>command<span class="token punctuation">]</span>

Available Commands:
  <span class="token function">help</span>        Help about any <span class="token function">command</span>
  scan        Scan endpoint <span class="token keyword">for</span> NoSQL Injection vectors
  version     Prints the current version

Flags:
      --config string       config <span class="token function">file</span> <span class="token punctuation">(</span>default is <span class="token variable">$HOME</span>/.nosqli.yaml<span class="token punctuation">)</span>
  -d, --data string         Specify default post data <span class="token punctuation">(</span>should not include any injection strings<span class="token punctuation">)</span>
  -h, --help                <span class="token function">help</span> <span class="token keyword">for</span> nosqli
  -p, --proxy string        Proxy requests through this proxy URL. Defaults to HTTP_PROXY environment variable.
  -r, --request string      Load <span class="token keyword">in</span> a request from a file, such as a request generated <span class="token keyword">in</span> Burp or ZAP.
  -t, --target string       target url eg. http://site.com/page?arg<span class="token operator">=</span>1
  -u, --user-agent string   Specify a user agent

Use <span class="token string">"nosqli [command] --help"</span> <span class="token keyword">for</span> <span class="token function">more</span> information about a command.

$ nosqli scan -t http://localhost:4000/user/lookup?username<span class="token operator">=</span>test
Running Error based scan<span class="token punctuation">..</span>.
Running Boolean based scan<span class="token punctuation">..</span>.
Found Error based NoSQL Injection:
  URL: http://localhost:4000/user/lookup?<span class="token operator">=</span><span class="token operator">&amp;</span>username<span class="token operator">=</span>test
  param: username
  Injection: username<span class="token operator">=</span>'
</code></pre>
<h2 id="using-nosqli">Using NoSQLi</h2>
<figure class="kg-card kg-image-card kg-card-hascaption"><img decoding="async" class="kg-image" src="https://nullsweep.com/content/images/2020/09/nosqli_demo_nosql_injection_scan.gif" alt=""><figcaption>nosql scanning using nosqli</figcaption></figure>
<p>It has a simple and flexible CLI interface for scanning. You can pass in a target URL with GET parameters that need to be scanned, or a saved request with POST data. The scanner is smart enough to know if the data is JSON or form data, and will inject either way.</p>
<p>The configurations currently support running through a proxy (so you can view the generated traffic in Burp or similar software) and changing the user agent.</p>
<h2 id="scanning-types">Scanning Types</h2>
<p>NoSQLi has the most commonly found injection vectors implemented:</p>
<ol>
<li><strong>Error Scans: </strong>Look for known error strings in responses from the server.</li>
<li><strong>Blind Boolean Injections</strong>: When the page doesn&#8217;t return errors, but does return different data when <code>true</code> or <code>false</code> is returned from the database (or when some records are retrieved vs. no records)</li>
<li><strong>Timing based injections</strong>: When all else fails, if the database sends a delayed response after a successful injection.</li>
</ol>
<h2>&nbsp;</h2>
<h2 id="using-nosqli-with-requests">Using NoSQLi with Requests</h2>
<p>A key feature missing from a few previous scanners was the ability to export a request from a proxy and run the injections based on that. NoSQLi can leverage this easily, and keeps all the header information, including things like user agent.</p>
<p>While the tool does not yet support importing a full session log and executing tests against all requests sequentially, saving a standard HTTP request to a file and referencing that file allows repeatable tests, or extraction from other tools such as Burp.</p>
<h2 id="installing-nosqli">Installing NoSQLi</h2>
<p>The <a href="https://github.com/Charlie-belmer/nosqli">github page</a> has all the instructions. You can build from source or download and run the appropriate <a href="https://github.com/Charlie-belmer/nosqli/releases">executable</a> for your system.</p>
</section>
</section>
<p>The post <a href="http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/">NoSQLi &#8211; A Fast NoSQL Injection Scanner</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
