Hackers of India

Pentesting NoSQL DB’s with NoSQL Exploitation Framework

By  Francis Alexander  on 23 Jun 2014 @ Hackinparis

This talk covers following tools where the speaker has contributed or authored
NOSQL-EXPLOITATION-FRAMEWORK

Presentation Material

Abstract

The talk focuses on:

Why NoSQL hasn’t solved the problem yet Why the DB administrator should worry as the default security could cost you your job. How an attacker with just an IP could take down the server and perform a resource exhaustion attack Various exploitation techniques such as timing based attacks similar to blind SQL injection with no feedback from the web application Discussion on why NoSQL encryption techniques have failed and why they aren’t secure How an attacker could leverage the various API’s within NoSQL for JSON-Injection 0-day Bug in PHP Couch Driver which helps an attacker to leverage various resources.

AI Generated Summarymay contain errors

Here is a summarized version of the content:

Main Points

Security Issues

NoSQL Exploitation Framework

Future Updates