hunt-nosqli

Community

Hunt NoSQLi: detect and exploit NoSQL injections.

Authorelementalsouls
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Identify and exploit NoSQL injection vulnerabilities across MongoDB, CouchDB, and Redis by leveraging operator injections such as $where, $regex, $gt, and $ne, enabling authentication bypass and data exfiltration during authorized testing.

Core Features & Use Cases

  • Operator injection techniques for MongoDB: $where, $regex, $gt, $ne; NoSQLi payloads to bypass login and enumerate data.
  • Redis and CouchDB exposure patterns: command injection via misconfigured endpoints and exposed admin UI; data dumping workflows.
  • Real-world scenarios include authenticated bypass in MongoDB-backed apps and data extraction from user collections.

Quick Start

Initiate an authorized NoSQL injection test against a target using MongoDB, CouchDB, or Redis to validate vulnerability presence.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: hunt-nosqli
Download link: https://github.com/elementalsouls/Claude-BugHunter/archive/main.zip#hunt-nosqli

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 510,000+ vetted skills library on demand.