Mongodb Attack

MongoDB 未授权访问与 NoSQL 注入利用。当发现目标开放 27017 端口、MongoDB 服务无认证、Web 应用使用 MongoDB 后端存在 NoSQL 注入、或需要从 MongoDB 提取数据时使用。覆盖未授权访问、数据库枚举与导出、NoSQL 注入($ne/$regex/$where/盲注)、JavaScript 执行(mapReduce/eval)、权限提升、GridFS 文件提取、配置文件凭据

netvar1337 9fa006e 2 files · 25.8 KB Updated

File contents

netvar1337/agent-skill-canon/tree/main/skills/aboutsecurity/exploit/network-service/mongodb-attack commit 9fa006e72c

Frequently asked questions

npx skillmds@latest add netvar1337/mongodb-attack