This document explains how to run injection_probe.py from the command line and how to map custom request fields used by your own backend login form.
Before running the probe, confirm these 5 items:
- You have explicit authorization to test this target.
- The URL points to the real login endpoint (
actiontarget), not just the page URL. - You know the form method and set matching transport (
POST/GETform ->--transport form, JSON API ->--transport json). - You mapped the correct identity and secret fields (
--username-field,--password-field). - If authentication middleware is in front, required headers/session values are included (for example with
--header).
This workflow is based on the most useful pattern from common SQL injection scanners: extract form metadata first, then test the right fields.
- Open the login page in your browser and inspect the form.
- Confirm these details:
- Form
actionendpoint (for example/login) - Form
method(POSTorGET) - Input field names (for example
username,password,email,passphrase)
- Run this tool with matching field names and transport.
- Start with summary output, then use
--tableonly when you need full detail. - Filter to meaningful status codes with
--result-status(for example200,302) to focus on likely bypass behavior.
Why this helps:
- Correct field names and method selection dramatically reduce false negatives.
- It mirrors how scanners that parse forms (BeautifulSoup-style extraction) prepare requests before payload testing.
injection_probe.py sends baseline and crafted login payloads to a login endpoint and reports signals that may indicate weak SQL injection or MongoDB NoSQL injection handling.
It probes both username and password fields. For MongoDB-specific checks, it includes payloads equivalent to username[$ne]=1 and password[$ne]=1 for form requests and object-operator payloads for JSON requests.
It is a heuristic probe, not a formal penetration test.
Use this only on systems you own or where you have explicit permission.
The CLI requires --authorized so it does not run by accident.
- Python 3.9+
requests
Install dependency:
python3 -m pip install requestspython3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorizedIf your backend is vulnerable to bracket-style payload parsing, run in form mode to send probes such as username[$ne]=1 and password[$ne]=1:
python3 injection_probe.py \
--url "http://10.112.190.6/login" \
--user-account "attendant" \
--transport form \
--authorized \
--pretty--url(required): Login endpoint URL.--user-account(required): Username or account value to test.--authorized(required flag to execute): Confirms you are permitted to test.--password(optional, default:invalid-password-for-probe): Password sent in probe requests.--transport(optional, default:json):jsonorformrequest body.--username-field(optional, default:username): Name of the username field sent in request body.--password-field(optional, default:password): Name of the password field sent in request body.--timeout(optional, default:10): Timeout in seconds.--header(optional, repeatable): Extra header inKey:Valueformat.--rotate-user-agents(optional): Rotate through User-Agents for each request.--user-agent(optional, repeatable): Provide your own User-Agent values; if set with--rotate-user-agents, these are used as the rotation pool.--ua-browser(optional, default:random): Browser family preference for fake-useragent rotation. Values:random,chrome,firefox,safari,edge.--table(optional): Full CLI grid table output with all findings.--json(optional): Compact JSON output.--pretty(optional): Pretty JSON output.--result-status(optional, repeatable): Only show findings with selected HTTP status codes. Example:--result-status 200,302.
If no output flag is provided, output defaults to a compact summary view using a HashSight-style fixed-width terminal table.
Note on MongoDB probes:
--transport jsonincludes payloads like{ "password": { "$ne": "1" } }.--transport jsonalso includes bracket-key variants for username/password to catch permissive parsers.--transport formincludes payloads likeusername[$ne]=1andpassword[$ne]=1.
Interpretation note:
- A vulnerable login endpoint typically shows a behavioral change (for example a success, token, redirect, or different status code) when an operator payload is used.
- This probe does not dump all users/passwords. If data is returned, that indicates a separate endpoint/query exposure issue, not normal login behavior.
If your backend expects field names other than username and password, pass your own names.
Example: backend expects email and passphrase:
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "staff@bytelotus.com" \
--username-field "email" \
--password-field "passphrase" \
--transport form \
--authorizedWhen you discover fields from a form, map them into this tool like this:
- Choose the two authentication fields:
- Identity field: username/email/staffId/etc. ->
--username-field - Secret field: password/passphrase/pin/etc. ->
--password-field
- Identity field: username/email/staffId/etc. ->
- Match the submission encoding:
- HTML form submit (
application/x-www-form-urlencoded) ->--transport form - JSON API login endpoint ->
--transport json
- HTML form submit (
- Keep non-auth fields fixed using
--headeror backend defaults (for example CSRF/session headers if required). - Provide a valid-looking account value via
--user-accountso probe behavior resembles real login flow.
Field selection rules (recommended):
- Include fields with names like
user,username,email,login,staffId,accountas identity candidates. - Include fields like
pass,password,passphrase,pinas secret candidates. - Do not map submit button names as auth fields.
- Hidden fields (CSRF, nonce, token) are support fields; keep them valid if your endpoint requires them.
Quick examples:
Form uses email + passphrase:
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "staff@bytelotus.com" \
--username-field email \
--password-field passphrase \
--transport form \
--authorizedAPI uses staffId + pin in JSON:
python3 injection_probe.py \
--url "https://api.your-app.com/auth/login" \
--user-account "CABANA-207" \
--username-field staffId \
--password-field pin \
--transport json \
--authorizedExample: backend expects guestId and pin:
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "CABANA-207" \
--username-field "guestId" \
--password-field "pin" \
--transport json \
--authorizedUse --header multiple times.
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--header "Authorization: Bearer YOUR_TOKEN" \
--header "X-Tenant: bytelotus" \
--authorizedEnable rotation (defaults to fake-useragent source):
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--rotate-user-agentsUse your own User-Agent pool:
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--rotate-user-agents \
--user-agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36" \
--user-agent "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"Use fake-useragent rotation:
python3 -m pip install fake-useragent
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--rotate-user-agents \
--ua-browser chromeIf fake-useragent is not available at runtime, the script returns an error. You can still run by passing explicit --user-agent values.
Summary output (default):
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorizedThe summary includes a "Worked Vulnerabilities" section that only lists payloads that triggered a positive vulnerability signal.
Full findings table output:
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--tableOnly show selected status codes (for example 200 and 302):
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--result-status 200,302Pretty JSON (human readable):
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--prettyCompact JSON (for scripts/CI):
python3 injection_probe.py \
--url "https://your-app.com/login" \
--user-account "attendant" \
--authorized \
--json-
Error: missing
--authorized- Add
--authorizedonly when you have explicit permission.
- Add
-
HTTP timeout errors
- Increase timeout, for example:
--timeout 30.
- Increase timeout, for example:
-
Wrong field names
- Match your API contract using
--username-fieldand--password-field.
- Match your API contract using
-
Backend expects form data, not JSON
- Set
--transport form.
- Set
Given your form inputs are named username and password, this is sufficient:
python3 injection_probe.py \
--url "https://your-host/login" \
--user-account "attendant" \
--authorizedIf your server later renames them, only update flags:
python3 injection_probe.py \
--url "https://your-host/login" \
--user-account "attendant" \
--username-field "staffId" \
--password-field "passphrase" \
--authorized