A small tool I made for automating enumeration by NoSQL injection
For example, you can enumerate what variables this
has and get useful database fields.
You can run multiple lines of code separated with ;
, and the cli will output what you put after return
at the end.
The repo also contains a small section detailing how the injection works (with some bypasses), hopefully someone will find it useful in their understanding of attacking Mongo.