MongoDB will not prevent NoSQL injections in your Node.js app
blog.sqreen.io
blog.sqreen.io
In addition to the fact that you can't execute arbitrary commands with this example, the example itself is flawed. If the programmer's intention was to exclude "secret projects" from all searches, then they should have written the query to do that. They didn't, and allowed multiple other ways of accessing those records.
Writing some code that does something different to what you intended it to do is not a NoSQL injection, it's just bad code.
You could use $exists, $gt, $eq, $ne, $in, $nin, regex, and all kinds of other ways to query what you want.
If the programmer wanted to exclude "secret projects" the query should have had a form similar to
{ $and: [{ type: { $ne: 'secret projects' }}, <rest of query>] }
It's the same thing here
Get informed: http://rethinkdb.com
r.table('users').filter(<here>).run(conn, callback);
of course if you use the chainable syntax
r.table('users').filter(r.row("age").eq(30)).run(conn, callback);
you can prevent it but that's not the point. It has nothing to do with Mongodb.
Exactly the same could be said about SQL injection, and its solution is prepared queries with value placeholders, which is an idea over a dozen years old. Apparently MongoDB has not caught up yet with SQL from decade ago.
What is needed is server side validation. Pretty much the same as client side, but most of the time a bit more robust. The problem is validating ALL the input. Like, creating this comment. Validation is really easy for this comment.
But what about something where you upload images? PDFs are well known attack vectors. So are SVGs. How can you be sure there's nothing hiding in those? It's possible. It just becomes increasingly difficult to cover each case.
-- edit grammer --