Skip to main content
Hackviser Training

NoSQL Injection

6 sections3 tools

Training Overview

The "NoSQL Injection" training comprehensively teaches how injection attacks in NoSQL databases work and how to protect against these attacks. The training starts with the structure of NoSQL databases and covers the fundamental principles of NoSQL Injection attacks and commonly used attack methods.

What you will learn

  • The fundamental differences between SQL and NoSQL databases.
  • How to identify and exploit NoSQL injection vulnerabilities.
  • How to perform time-based blind NoSQL injection attacks.
  • Best practices for preventing NoSQL injection in applications.

Tools you will use

  • Burp Suite
  • A web browser
  • NoSQLMap (Conceptual)

Prerequisites

  • Understanding of web application architecture.
  • Familiarity with JavaScript and JSON is highly beneficial.
  • Experience with a web proxy like Burp Suite.

Who this is for

  • Web Penetration Testers.
  • Developers working with NoSQL databases (e.g., MongoDB, CouchDB).
  • Application Security Specialists.

Training sections

  1. 1Introduction
  2. 2NoSQL Databases
  3. 3NoSQL Injection
  4. 4Time Based NoSQL Injection
  5. 5Preventing NoSQL Injection Vulnerabilities
  6. 6Exam

Continue learning

Practice the topic in a lab or continue with a related Hackviser guide.