I think the search-users route is still injectable passing {"$ne": null} as username. The login instead seems safe but i don't know if there is some trick to make Mongo ignore the passToTest parameter and only use the injectable username (pls some Mongo expert respond this). Anyway nice video, keep it up
Guau increible, te descubri por casualidad. I love your whiteups and reviews!
Need more of white box testing please.. This is Great..
Awesome, keep it up!👏
Thanks that was fun
I learned so much thing, nice video. Thanks..
I think the search-users route is still injectable passing {"$ne": null} as username. The login instead seems safe but i don't know if there is some trick to make Mongo ignore the passToTest parameter and only use the injectable username (pls some Mongo expert respond this). Anyway nice video, keep it up
how did you know to use that payload as the username?
check out the link to the full writeup for that!
👍👍
wow