daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cypher-injection-neo4j.md (1372B)


      1 ---
      2 title: "Cypher Injection (Neo4j)"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/sql-injection/cypher-injection-neo4j.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/cypher-injection-neo4j.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Cypher Injection (Neo4j)
     14 
     15 Cypher injection occurs when an application constructs a Neo4j Cypher query by concatenating untrusted input. An attacker may alter the query structure to read or modify graph data and, depending on enabled procedures and cloud integrations, reach additional secrets or services.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     16 
     17 Use parameterized queries for values and allowlist any identifiers or query fragments that cannot be parameterized. The references below contain practical discovery and exploitation examples.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 ## References
     20 
     21 - [1] [Neo4jection: Secrets, Data, and Cloud Exploits](https://www.varonis.com/blog/neo4jection-secrets-data-and-cloud-exploits)
     22 - [2] [The Most Underrated Injection of All Time — Cypher Injection](https://infosecwriteups.com/the-most-underrated-injection-of-all-time-cypher-injection-fa2018ba0de8)