What problem does it solve?
This Skill eliminates the risk of missing critical SQL injection (including NoSQL injection) vulnerabilities during security assessments, which are high-severity flaws that can lead to full data exfiltration, authentication bypass, and even remote code execution on target systems.
Core Features & Use Cases
- Modern injection variant coverage: Includes NoSQL injection (MongoDB $regex, $where operators), ORM raw-fragment bypasses (Django, Sequelize, Mongoose), second-order SOQL injection, time-based blind SQLi in GraphQL resolvers, and OIDC-proxy backend SQLi, all sourced from 12 verified public bug bounty reports.
- Structured hunting workflow: Step-by-step methodology for identifying injectable parameters, confirming vulnerabilities via error-based, boolean-based, and time-based detection, and escalating impact to demonstrate full exploitability.
- Real-world impact context: Includes verified case studies from Rocket.Chat, Mozilla, Django, and enterprise targets to help users demonstrate business risk and meet bug bounty report quality standards.
Quick Start
Use the hunt-sqli skill to audit all input parameters on your authorized target's search, filter, API, and authentication endpoints for SQL injection and NoSQL injection flaws, following the provided methodology to confirm and document findings for your penetration test or bug bounty report.