SKILL: NoSQL Injection — Expert Attack Playbook
AI LOAD INSTRUCTION: NoSQL injection is fundamentally different from SQL injection. Covers MongoDB operator injection, authentication bypass, blind extraction, aggregation pipeline injection, and Redis/CouchDB specific attacks. Very commonly missed by testers who only know SQLi patterns.
1. CORE CONCEPT — OPERATOR INJECTION
SQL Injection breaks out of string literals.
NoSQL Injection injects query operators that change query logic.
MongoDB example — normal query:
Injection via JSON operator:
→ Becomes: find({username:"admin", password:{$gt:""}}) → password > "" → always true!
2. MONGODB — LOGIN BYPASS
JSON Body Injection (API with JSON Content-Type)
PHP $_POST Array Injection (URL-encoded form)
Ruby / Python params Array Injection
Same as PHP — use bracket notation to inject objects:
%24 = URL-encoded $
3. MONGODB OPERATORS FOR INJECTION
4. BLIND DATA EXTRACTION VIA $REGEX
Like binary search in SQLi, use $regex to extract field values character by character:
Response difference: successful login vs failed login = boolean oracle.
Automate with NoSQLMap or custom script with binary search on character set.
5. MONGODB $WHERE INJECTION (JS EXECUTION)
$where evaluates JavaScript in MongoDB context.
Can only use current document's fields — not system access. But allows logic abuse:
Limit: $where doesn't give OS command execution — server-side JS injection (not to be confused with command injection).
6. AGGREGATION PIPELINE INJECTION
When user-controlled data enters $match or $group stages:
Inject operators to bypass:
7. HTTP PARAMETER POLLUTION FOR NOSQL
Some frameworks (Express.js, PHP) parse repeating parameters as arrays:
Use qs library parse behavior in Node.js:
8. COUCHDB ATTACKS
HTTP Admin API (if exposed)
9. REDIS INJECTION
Redis exposed (6379) with no auth — command injection via input used in Redis queries:
Auth bypass (older Redis with requirepass using simple password):
10. DETECTION PAYLOADS
Send these to any input processed by NoSQL backend:
JSON variant test (change Content-Type to application/json if endpoint is form-based):
11. NOSQL VS SQL — KEY DIFFERENCES
12. TESTING CHECKLIST
13. BLIND NoSQL EXTRACTION AUTOMATION
$regex Character-by-Character Extraction (Python Template)
$regex via URL-encoded GET Parameters
Duplicate Key Bypass
14. AGGREGATION PIPELINE INJECTION
When user input reaches MongoDB aggregation pipeline stages:
$where JavaScript Execution
Reference: Soroush Dalili — "MongoDB NoSQL Injection with Aggregation Pipelines" (2024)
Note: $where runs JavaScript on the server. Besides logic abuse and timing oracles, older MongoDB builds without a tight V8 sandbox historically raised RCE concerns; prefer treating any $where sink as high risk.


