Bypassing Authentication
Authentication Bypass Example
$query = new MongoDB\Driver\Query(array(
"email" => $_POST['email'],
"password" => $_POST['password']
));
$cursor = $manager->executeQuery('mangomail.users', $query);db.users.find({
email: "<email>",
password: "<password>"
});Bypass Techniques
1) $ne (not equal) operator
2) $regex (pattern matching)
3) $gt/$gte (greater than/equal)
4) Targeted bypass (known email)
Key Points
Prevention
Last updated