A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


NoSQL Injections: Moving Beyond 'or '1'='1' - Matt Bromiley Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)

NoSQL Injections: Moving Beyond 'or '1'='1'
Matt Bromiley
Derbycon 2014

Gone are the days of SELECT *... Hadoop, Mongo, Elastic , search. NoSQL databases are all the rage these days, as companies migrate some, if not all, of their data to these new storage types. As infosec practitioners encounter these bad boys, we need to know what to do with them. This talk will combine viewpoints of NoSQL injections and the footprints left behind. Using MongoDB as an example, attendees will be shown basic Mongo operations and through log analysis, determine which operations are logged and which are not. We’ll then build up our NoSQL injection skills, making Mongo and Elasticsearch sing. Attendees should be prepared to learn some neat NoSQL tricks, and proceed comfortably knowing what’s logged and what’s not.

Back to Derbycon 2014 video list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast