Burp Suite User Forum

Create new post

Return 500 during intruder attack with Lab: Exploiting NoSQL operator injection to extract unknown fields

Nicolas | Last updated: Sep 20, 2024 11:23AM UTC

Hello, When doing this lab : https://portswigger.net/web-security/nosql-injection/lab-nosql-injection-extract-unknown-fields The intruder attack return error 500 for each request with this payload : {"username":"carlos","password":{"$ne":""}, "$where":"function(){if(Object.keys(this)[3].length == §1§) return 1; else return 0; }"} (I can browse the lab with when using Burp's browser)

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.