NoSQL Exploitation Framework

By Francis Alexander on 15 Feb 2014 @ Nullcon
πŸ’» Source Code πŸ”— Link
#red-teaming #application-pentesting #security-tools #dynamic-analysis #network-forensics #data-leak
Focus Areas: πŸ”’ Data Privacy & Protection , πŸ” Application Security , βš™οΈ DevSecOps , 🚨 Incident Response , 🦠 Malware Analysis , 🌐 Network Security , 🎯 Penetration Testing
This Tool Demo covers following tools where the speaker has contributed or authored
NOSQL-EXPLOITATION-FRAMEWORK

Abstract

The Tool focuses on scanning and exploiting NoSQL Databases which makes the pentesters life easy. The tool currently has support for Mongo,Couch-db and Redis,with further additions to be made soon.It supports Enumerating NoSQL Db’s,Dumping Nosql db’s,Dictionary attacks and Shodan Search currently.