nosqli
A fast NoSQL scanner and injector. For finding sites vulnerable to NoSQL injection, Mongo in particular.
Details
Category: Vulnerabilities
Publisher: trickest
Created Date: 9/7/2021
Container: quay.io/trickest/nosqli:6fce3eb
Source URL: https://github.com/Charlie-belmer/nosqli
Parameters
Command:
--data
- Specify default post data (should not include any injection strings)Command:
--https
- Always send requests as HTTPS (Defaults to HTTP when using request files)Command:
--proxy
- Proxy requests through this proxy URL.Command:
--config
- config fileCommand:
--target
- Target url eg. http://site.com/page?arg=1Command:
--request
- Load in a request from a file, such as a request generated in Burp or ZAP.Command:
--user-agent
- Specify a user agent