EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard
A web application utilizes a NoSQL database for storing user profiles. A penetration tester discovers that by injecting specific characters like `{$ne: null}` into a search query parameter, they can bypass authentication and view all user profiles without providing credentials. Which type of injection attack is this tester leveraging?
- ALDAP Injection
- BCommand Injection
- CNoSQL Injection
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: C. NoSQL Injection
The use of specific NoSQL query operators like `{$ne: null}` (meaning 'not equal to null') to bypass authentication in a web application backed by a NoSQL database is a clear indicator of a NoSQL Injection attack. This attack exploits vulnerabilities in how NoSQL databases handle user input in queries.
Why the other options are wrong
- A. LDAP Injection targets Lightweight Directory Access Protocol (LDAP) directories, not NoSQL databases.
- B. Command Injection executes arbitrary system commands on the server, unrelated to database query manipulation.
- D. SQL Injection targets relational databases with SQL syntax, not NoSQL databases.
NoSQL Injection
An injection attack that exploits vulnerabilities in NoSQL databases by injecting malicious NoSQL query syntax to bypass authentication, retrieve unauthorized data, or execute arbitrary commands.
- Targets databases like MongoDB, Cassandra, Redis.
- Syntax varies depending on the specific NoSQL database.
- Often involves manipulating JSON or BSON queries.
Memory trick: NoSQL means 'No Standard Query Language' for injection.