Skip to main content

Injection into APIs: SQLi & NoSQLi

Injection isn't just for web forms. APIs are vulnerable too. Learn how to inject NoSQL queries (`{"$gt": ""}`) into JSON payloads to bypass login, and how to spot SQL/Command Injection in REST endpoints "Order By" params.

5 chapters
85m total

Sign in to continue

Sign in to unlock lessons based on your plan and track your progress.