Introduction to NoSQL Injection  

Skills Assessment I


MangoAPI has contracted you to test their API for NoSQL injection vulnerabilities, specifically the login endpoint. The endpoint is documented as follows:

POST /api/login

  • Log in and receive a user's authorization token
  • Request requires the parameters: username and password
  • Request accepts parameters in a JSON body
  • Request requires the header Content-Type: application/json

For testing purposes, MangoAPI provisioned you an account with the credentials pentest:pentest.

Use the skills learned in this module to assess the API for NoSQL injection flaws and submit the flag that you discover in the process.

/ 1 spawns left

Waiting to start...

Questions

Answer the question(s) below to complete this Section and earn cubes!

Click here to spawn the target system!

Target: Click here to spawn the target system!

+10 Streak pts

Previous

+10 Streak pts

Next