WEBVTT

0:00:11.120000 --> 0:00:14.720000
 No SQL or NoSQL fundamentals.

0:00:14.720000 --> 0:00:19.740000
 So welcome everyone to the NoSQL
 injection section of this course.

0:00:19.740000 --> 0:00:23.080000
 Now this is going to be the final section
 of this course and I will typically

0:00:23.080000 --> 0:00:25.380000
 consider it to be a bonus section.

0:00:25.380000 --> 0:00:29.600000
 The reason for that is obviously primarily
 because we will not be diving

0:00:29.600000 --> 0:00:32.220000
 too deep into NoSQL injection.

0:00:32.220000 --> 0:00:35.840000
 I added it here as sort of a primer because
 we will be exploring it later

0:00:35.840000 --> 0:00:41.700000
 on even in more advanced web application
 penetration testing certification.

0:00:41.700000 --> 0:00:45.960000
 So in the beginning of the course, when
 we are talking about databases,

0:00:45.960000 --> 0:00:51.740000
 I briefly introduced you to NoSQL databases
 and showed you how they operate

0:00:51.740000 --> 0:00:57.240000
 or how they work in relation to your
 standard SQL or relational databases.

0:00:57.240000 --> 0:01:01.080000
 So in this video, what I am going to
 do is again reintroduce you to NoSQL

0:01:01.080000 --> 0:01:06.160000
 databases and sort of cover pretty much
 everything that you need to know

0:01:06.160000 --> 0:01:06.900000
 or the essentials.

0:01:06.900000 --> 0:01:12.660000
 And then we will also be taking a look
 at a practical live lab where we

0:01:12.660000 --> 0:01:18.360000
 will be interacting with a MongoDB server
 or MongoDB as it were to show

0:01:18.360000 --> 0:01:24.540000
 you how it differs from a typical or how
 it differs to a typical relational

0:01:24.540000 --> 0:01:29.540000
 database with regards not only to its
 structure, but also the commands

0:01:29.540000 --> 0:01:31.580000
 or the queries that you can run.

0:01:31.580000 --> 0:01:36.700000
 So to begin with, what is
 NoSQL or a NoSQL database?

0:01:36.700000 --> 0:01:42.880000
 Well, NoSQL databases, also known as
 not only SQL databases, are a class

0:01:42.880000 --> 0:01:46.820000
 of database management systems that
 provide a non-relational approach

0:01:46.820000 --> 0:01:49.880000
 for storing and retrieving data.

0:01:49.880000 --> 0:01:54.440000
 Unlike traditional relational databases,
 which organize data into tables

0:01:54.440000 --> 0:01:59.600000
 with predefined schemas as we have been
 able to see, NoSQL databases offer

0:01:59.600000 --> 0:02:04.400000
 more flexible data models, which are
 useful in certain cases, that can

0:02:04.400000 --> 0:02:08.760000
 handle unstructured, semi-structured
 and rapidly evolving data.

0:02:08.760000 --> 0:02:13.680000
 NoSQL databases emerged as a response to
 the need for scalability, performance

0:02:13.680000 --> 0:02:17.180000
 and agility in handling modern
 data types and workloads.

0:02:17.180000 --> 0:02:24.060000
 Now, I can't or I will not dive into
 the nitty gritty of the advantages

0:02:24.060000 --> 0:02:29.360000
 of NoSQL databases and their deployment
 models or the deployment environments

0:02:29.360000 --> 0:02:32.640000
 where you typically see them deployed
 over relational databases.

0:02:32.640000 --> 0:02:39.140000
 But the primary reason why some developers
 or some companies utilize NoSQL

0:02:39.140000 --> 0:02:43.940000
 databases is primarily based on the type
 of data they're storing, if it's

0:02:43.940000 --> 0:02:49.340000
 typically rapidly changing and secondly
 for scalability, as I've just

0:02:49.340000 --> 0:02:52.600000
 shown, and I'll explain the scalability
 aspect in a few seconds.

0:02:52.600000 --> 0:02:57.620000
 So when you talk about NoSQL databases,
 the important thing to note is

0:02:57.620000 --> 0:02:59.540000
 that there are types of NoSQL databases.

0:02:59.540000 --> 0:03:03.580000
 Now, this list is by no
 means comprehensive.

0:03:03.580000 --> 0:03:07.420000
 This is just the common ones or these
 are examples of the common ones

0:03:07.420000 --> 0:03:08.620000
 that you will see.

0:03:08.620000 --> 0:03:15.620000
 So the first and the most popular
 are key value stores, right?

0:03:15.620000 --> 0:03:17.000000
 Key value pairs.

0:03:17.000000 --> 0:03:22.300000
 The value can be any type of data such
 as text, JSON or binary objects.

0:03:22.300000 --> 0:03:27.820000
 Examples of key value store databases
 include Redis, React and Amazon

0:03:27.820000 --> 0:03:31.560000
 DynamoDB. Redis being the most popular
 of them all and we'll touch on

0:03:31.560000 --> 0:03:35.460000
 Redis shortly. We then have document
 databases, which is what we're going

0:03:35.460000 --> 0:03:37.820000
 to be taking a look at
 in the practical demo.

0:03:37.820000 --> 0:03:42.680000
 So document databases store and retrieve
 data in JSON-like documents.

0:03:42.680000 --> 0:03:46.780000
 And documents can vary in structure
 and the database provides features

0:03:46.780000 --> 0:03:50.260000
 for querying and indexing based
 on the documents content.

0:03:50.260000 --> 0:03:54.500000
 MongoDB and Couchbase serve our
 popular document databases.

0:03:54.500000 --> 0:03:57.140000
 We then have columnar databases.

0:03:57.140000 --> 0:04:01.580000
 Columnar databases organize data into
 columns rather than rows, making

0:04:01.580000 --> 0:04:05.140000
 them efficient for analytical workloads
 and handling large volumes of

0:04:05.140000 --> 0:04:10.140000
 data. Examples of these are Apache
 Cassandra and Apache HBase.

0:04:10.140000 --> 0:04:12.400000
 So those are the primary types.

0:04:12.400000 --> 0:04:16.740000
 Now, that brings us to the
 critical point here.

0:04:16.740000 --> 0:04:21.080000
 And that is what is the difference between
 a traditional SQL relational

0:04:21.080000 --> 0:04:25.480000
 database and a NoSQL database?

0:04:25.480000 --> 0:04:28.540000
 Well, firstly, we have the type, right?

0:04:28.540000 --> 0:04:32.540000
 So in this particular case, SQL databases
 are most likely going to be

0:04:32.540000 --> 0:04:38.960000
 relational and NoSQL databases are
 not relational or non-relational.

0:04:38.960000 --> 0:04:43.180000
 And I explained how relational databases
 work, so I'll not dive into that

0:04:43.180000 --> 0:04:48.080000
 right now. As for the data storage model,
 you can see that in SQL databases,

0:04:48.080000 --> 0:04:52.060000
 you typically have tables with
 fixed rows and columns.

0:04:52.060000 --> 0:04:57.520000
 In NoSQL databases, the data storage
 model is typically unstructured.

0:04:57.520000 --> 0:05:02.960000
 The storage in JSON files and there's
 typically use of key value pairs.

0:05:02.960000 --> 0:05:07.400000
 So tables and rows with dynamic columns,
 as you'll see once we get started.

0:05:07.400000 --> 0:05:12.060000
 As for the database schema with SQL
 databases, you typically see that

0:05:12.060000 --> 0:05:18.340000
 the static or rigid schema, which means
 very less likely to change or

0:05:18.340000 --> 0:05:22.820000
 are pretty much static because of the
 relational nature or the relational

0:05:22.820000 --> 0:05:25.080000
 nature of the actual data.

0:05:25.080000 --> 0:05:29.520000
 With NoSQL databases, the schema is dynamic
 or flexible for obvious reasons

0:05:29.520000 --> 0:05:32.800000
 because data is rapidly changing.

0:05:32.800000 --> 0:05:36.540000
 The structure of rows in this
 particular columns is dynamic.

0:05:36.540000 --> 0:05:40.980000
 So as a result, the schema needs
 to be dynamic or flexible.

0:05:40.980000 --> 0:05:44.160000
 Now this is the key point here
 and that's scalability.

0:05:44.160000 --> 0:05:48.280000
 So with SQL databases, it's vertical scalability
 where you need to increase

0:05:48.280000 --> 0:05:54.120000
 resources, physical or hardware resources,
 in order to scale performance.

0:05:54.120000 --> 0:05:57.900000
 With NoSQL databases, it's
 horizontal scaling.

0:05:57.900000 --> 0:06:02.540000
 As for the language, SQL databases
 is fairly simple.

0:06:02.540000 --> 0:06:05.980000
 It utilizes the structured query language
 as we've been able to see.

0:06:05.980000 --> 0:06:10.600000
 With the NoSQL database, it's the
 unstructured query language.

0:06:10.600000 --> 0:06:15.020000
 Typically, the NoSQL databases that
 I've just highlighted the examples

0:06:15.020000 --> 0:06:19.160000
 of, which we'll take a look at shortly,
 usually have their own query language

0:06:19.160000 --> 0:06:25.400000
 in some cases and also have some the
 capability for Boolean or logical

0:06:25.400000 --> 0:06:27.800000
 operations which will also highlight.

0:06:27.800000 --> 0:06:32.120000
 And that's where the whole NoSQL
 injection comes into play.

0:06:32.120000 --> 0:06:35.620000
 We've talked about the schema, but I
 wanted to dive deeper a little bit

0:06:35.620000 --> 0:06:39.820000
 into that or a little more into that
 where to sort of highlight what I

0:06:39.820000 --> 0:06:40.740000
 was talking about.

0:06:40.740000 --> 0:06:45.900000
 But with SQL databases, the schema is bound
 to the relationship or relationships

0:06:45.900000 --> 0:06:51.100000
 and NoSQL databases typically
 have a non-rigid schema.

0:06:51.100000 --> 0:06:55.780000
 As for the query complexity, this is where
 you factor in the query language.

0:06:55.780000 --> 0:06:59.240000
 So in the case of the structured query
 language, as you're able to tell,

0:06:59.240000 --> 0:07:04.360000
 it supports really complex queries
 that can perform multiple things at

0:07:04.360000 --> 0:07:09.320000
 one go, where you can combine different
 queries into one and combine their

0:07:09.320000 --> 0:07:15.100000
 results. Let's say a select statement
 using the union operator, so on

0:07:15.100000 --> 0:07:18.260000
 and so forth. So it supports
 really complex queries.

0:07:18.260000 --> 0:07:23.720000
 The disadvantage with NoSQL databases
 is while databases or NoSQL databases

0:07:23.720000 --> 0:07:28.040000
 like MongoDB have their own query language,
 they don't really support

0:07:28.040000 --> 0:07:33.640000
 advanced or complex queries in the same
 way that SQL database would, given

0:07:33.640000 --> 0:07:35.760000
 the fact that is relational.

0:07:35.760000 --> 0:07:40.260000
 So they support some really cool queries
 and some really advanced operations,

0:07:40.260000 --> 0:07:45.600000
 but not to the level that you would
 see with standard SQL database.

0:07:45.600000 --> 0:07:49.540000
 So those are the key differences
 between the two types here.

0:07:49.540000 --> 0:07:53.280000
 And again, I've not gone over all of
 them with regards to the technical

0:07:53.280000 --> 0:07:56.860000
 stuff, because I don't think that that's
 really important at this phase.

0:07:56.860000 --> 0:07:59.220000
 But this is what I'm referring
 to typically.

0:07:59.220000 --> 0:08:03.520000
 So if we take a look at on the left here,
 we have a standard SQL relational

0:08:03.520000 --> 0:08:10.480000
 database, where you have columns and rows
 and a column refers to the attribute.

0:08:10.480000 --> 0:08:13.520000
 And the rows are referred
 to records, right?

0:08:13.520000 --> 0:08:20.540000
 So particular entries with a NoSQL database
 like MongoDB, where you have

0:08:20.540000 --> 0:08:25.320000
 documents or the use of documents or
 records as it were, you can see that

0:08:25.320000 --> 0:08:29.480000
 data is stored in documents
 and its key value.

0:08:29.480000 --> 0:08:33.700000
 So prop one and then the data and the
 data could consist of multiple fields,

0:08:33.700000 --> 0:08:35.360000
 but we'll get to that.

0:08:35.360000 --> 0:08:37.340000
 And that's how it's stored.

0:08:37.340000 --> 0:08:40.000000
 And you may be asking yourself,
 why would you want to do that?

0:08:40.000000 --> 0:08:43.560000
 As I said, I'm not really going to dive
 deep into why you would want to

0:08:43.560000 --> 0:08:47.240000
 use one over the other, because again,
 that would go over the scope of

0:08:47.240000 --> 0:08:51.140000
 this course. But this is essentially
 the difference between them.

0:08:51.140000 --> 0:08:54.980000
 So it's very important that
 you keep this in mind.

0:08:54.980000 --> 0:08:59.180000
 Now, of course, we've talked a lot about
 this, but what are the most popular

0:08:59.180000 --> 0:09:03.860000
 NoSQL databases that you run into when
 performing a web app pen test?

0:09:03.860000 --> 0:09:06.780000
 And of course, this is by
 no means comprehensive.

0:09:06.780000 --> 0:09:10.520000
 Just from my experience, you'll typically
 find MongoDB being used quite

0:09:10.520000 --> 0:09:14.580000
 a lot. So MongoDB, as I've stated before,
 is a document database that

0:09:14.580000 --> 0:09:17.840000
 stores data in flexible
 JSON-like documents.

0:09:17.840000 --> 0:09:22.200000
 And it provides high scalability, automatic
 sharding, and a powerful query

0:09:22.200000 --> 0:09:27.620000
 language called the Mongo Query Language,
 or MQL, which I'll actually

0:09:27.620000 --> 0:09:30.960000
 be helping you with or helping
 you understand shortly.

0:09:30.960000 --> 0:09:32.180000
 We then have Cassandra.

0:09:32.180000 --> 0:09:35.620000
 Apache Cassandra is a distributed columnar
 database designed to handle

0:09:35.620000 --> 0:09:39.760000
 large amounts of data across
 multiple commodity servers.

0:09:39.760000 --> 0:09:44.260000
 It offers high availability, fault tolerance,
 and a linear scalability.

0:09:44.260000 --> 0:09:47.320000
 We then have Redis, which
 again is very popular.

0:09:47.320000 --> 0:09:51.100000
 Redis is an in-memory key value store
 that can be used as a database cache

0:09:51.100000 --> 0:09:52.580000
 or message broker.

0:09:52.580000 --> 0:09:56.780000
 It's typically used as a cache or message
 broker, and it supports a wide

0:09:56.780000 --> 0:10:02.100000
 range of data structures and provides
 high performance and low latency.

0:10:02.100000 --> 0:10:06.280000
 Now, this brings us to the NoSQL database
 query language, or what language

0:10:06.280000 --> 0:10:09.380000
 NoSQL database is utilized now.

0:10:09.380000 --> 0:10:13.540000
 NoSQL databases typically have their
 own query languages or interfaces

0:10:13.540000 --> 0:10:16.360000
 for data retrieval and manipulation.

0:10:16.360000 --> 0:10:20.600000
 And here are some examples of query languages
 used in popular NoSQL databases.

0:10:20.600000 --> 0:10:24.600000
 So as I've said, in the case of MongoDB,
 it utilizes a query language

0:10:24.600000 --> 0:10:28.300000
 called the MongoDB query language,
 also known as MQL.

0:10:28.300000 --> 0:10:31.820000
 And it provides a rich set of operators
 and functions for querying and

0:10:31.820000 --> 0:10:35.960000
 manipulating documents in the database,
 not as extensive as the structured

0:10:35.960000 --> 0:10:38.400000
 query language, but still
 pretty powerful.

0:10:38.400000 --> 0:10:40.120000
 We then have Redis.

0:10:40.120000 --> 0:10:44.040000
 Redis is primarily an in-memory data
 structure store and does not have

0:10:44.040000 --> 0:10:45.820000
 a traditional query language.

0:10:45.820000 --> 0:10:49.260000
 It provides a set of commands that operate
 on different data structures

0:10:49.260000 --> 0:10:52.800000
 like strings, lists, sets, and hashes.

0:10:52.800000 --> 0:10:55.780000
 Redis commands are typically used to
 perform operations such as reading

0:10:55.780000 --> 0:10:59.880000
 and writing data, data manipulation,
 and data exploration.

0:10:59.880000 --> 0:11:03.240000
 So essentially, modification
 of the data store.

0:11:03.240000 --> 0:11:08.060000
 And that brings us to the practical
 section of this video.

0:11:08.060000 --> 0:11:11.400000
 Where we'll be interacting
 with a MongoDB server.

0:11:11.400000 --> 0:11:14.560000
 And I'll be showing you some a little
 bit of the Mongo query language

0:11:14.560000 --> 0:11:16.920000
 and how you can sort of navigate
 around the database.

0:11:16.920000 --> 0:11:21.860000
 So you have an understanding, at least
 at a fundamental level of how NoSQL

0:11:21.860000 --> 0:11:25.100000
 databases work, primarily
 how they store data.

0:11:25.100000 --> 0:11:29.020000
 So I'm not going to highlight the syntax
 and the slides because as I said,

0:11:29.020000 --> 0:11:30.940000
 this is not really important
 at this phase.

0:11:30.940000 --> 0:11:33.940000
 I just want to introduce
 you to NoSQL injection.

0:11:33.940000 --> 0:11:38.700000
 And we start off by understanding how
 these databases work with regards

0:11:38.700000 --> 0:11:40.400000
 to the actual database itself.

0:11:40.400000 --> 0:11:44.420000
 So this lab will provide you with a
 terminal session where we'll be able

0:11:44.420000 --> 0:11:47.660000
 to immediately interact
 with the MongoDB server.

0:11:47.660000 --> 0:11:50.520000
 So you don't need to use your
 own Kali Linux system.

0:11:50.520000 --> 0:11:52.660000
 We don't need to use any other tools.

0:11:52.660000 --> 0:11:54.080000
 We'll just get started.

0:11:54.080000 --> 0:11:57.060000
 And again, you can go through
 the video first.

0:11:57.060000 --> 0:11:58.920000
 I would highly recommend
 that you do that.

0:11:58.920000 --> 0:12:02.020000
 However, if you're familiar with the
 Mongo query language, you can go

0:12:02.020000 --> 0:12:05.220000
 through the lab and then go through
 the video or the practical section

0:12:05.220000 --> 0:12:08.480000
 of this video. With that being said,
 let me start up the lab and switch

0:12:08.480000 --> 0:12:12.340000
 over and we can get started.

0:12:12.340000 --> 0:12:17.040000
 All right. So I am back within
 the lab environment.

0:12:17.040000 --> 0:12:20.800000
 And this is the lab environment you'll
 be provided with in a browser tab.

0:12:20.800000 --> 0:12:26.160000
 It'll provide you with a web SSH
 session on a as the user student.

0:12:26.160000 --> 0:12:31.440000
 So this particular Linux server already
 has a MongoDB or a MongoDB server

0:12:31.440000 --> 0:12:36.940000
 running. And in order to interact with
 the MongoDB server, we simply need

0:12:36.940000 --> 0:12:42.060000
 to type in Mongo and it enter and it's
 going to open up the MongoDB shell.

0:12:42.060000 --> 0:12:44.060000
 And from this point, we can get started.

0:12:44.060000 --> 0:12:47.740000
 Now the most important command here
 is going to be the help command.

0:12:47.740000 --> 0:12:52.000000
 If you ever lost with regards to commands
 or queries, just open it up.

0:12:52.000000 --> 0:12:56.120000
 And you can see that you
 can also utilize the db.

0:12:56.120000 --> 0:13:00.200000
 .help command right over here
 to get help on db methods.

0:13:00.200000 --> 0:13:04.900000
 You can also utilize the db.mycollection
.help command here, which will

0:13:04.900000 --> 0:13:06.900000
 give you help on collection methods.

0:13:06.900000 --> 0:13:11.700000
 Now I'll explain what collections are because
 I think this is quite important.

0:13:11.700000 --> 0:13:16.420000
 You can list out the databases collections,
 users, the profile, the logs,

0:13:16.420000 --> 0:13:18.840000
 etc. So very, very simple to use.

0:13:18.840000 --> 0:13:22.060000
 Not simple in a bad way, but
 just really functional.

0:13:22.060000 --> 0:13:24.520000
 Now we need to understand
 a few concepts here.

0:13:24.520000 --> 0:13:28.200000
 When we refer to a database, this
 is very similar to a SQL database.

0:13:28.200000 --> 0:13:30.580000
 We're referring to an actual database.

0:13:30.580000 --> 0:13:35.500000
 So if we say, for example,
 here, show DBS, right?

0:13:35.500000 --> 0:13:40.460000
 And in this particular case, it's typically
 recommended that you pretty

0:13:40.460000 --> 0:13:45.120000
 much end your queries with the actual
 semicolon, as you would do with

0:13:45.120000 --> 0:13:47.180000
 the structured query language.

0:13:47.180000 --> 0:13:50.860000
 But you can just hit enter and that's
 going to show you your databases.

0:13:50.860000 --> 0:13:54.480000
 So we have various databases here that
 look like they're storing different

0:13:54.480000 --> 0:13:58.660000
 types of data. So we have one called
 admin, city flag, local stats and

0:13:58.660000 --> 0:14:03.320000
 users. Now it's after this point when
 you go into each database that things

0:14:03.320000 --> 0:14:07.420000
 change from a standard relational
 database or a SQL database.

0:14:07.420000 --> 0:14:13.500000
 So if I was to navigate into a database,
 let's say in MySQL, what I would

0:14:13.500000 --> 0:14:15.860000
 be greeted with at that point is tables.

0:14:15.860000 --> 0:14:20.100000
 All right. Now what you'll be greeted with
 in the case of MongoDB is something

0:14:20.100000 --> 0:14:21.040000
 called a collection.

0:14:21.040000 --> 0:14:25.660000
 All right. Now a collection is a grouping
 of documents inside the database.

0:14:25.660000 --> 0:14:30.160000
 It's pretty much the same thing
 or a similar to a table in SQL.

0:14:30.160000 --> 0:14:35.540000
 And it stores different types of
 data based on its data type.

0:14:35.540000 --> 0:14:40.040000
 You know, essentially what you
 do with a relational database.

0:14:40.040000 --> 0:14:43.920000
 So we can go ahead and list out the
 collections, but I'll show you how

0:14:43.920000 --> 0:14:46.020000
 we would typically go through this.

0:14:46.020000 --> 0:14:50.980000
 The first thing you need to know how
 to do is obviously to to actually

0:14:50.980000 --> 0:14:52.720000
 select a particular database.

0:14:52.720000 --> 0:14:57.840000
 And then we can say, for example, in
 this case, let's try and use the

0:14:57.840000 --> 0:14:59.820000
 users database or interact with it.

0:14:59.820000 --> 0:15:05.180000
 In order to do that, we say use and
 we then say users or the actual name

0:15:05.180000 --> 0:15:05.800000
 of the database.

0:15:05.800000 --> 0:15:08.640000
 So there is going to say
 switch to DB users.

0:15:08.640000 --> 0:15:10.920000
 And then we can say show collections.

0:15:10.920000 --> 0:15:12.900000
 And that's the equivalent of show tables.


0:15:12.900000 --> 0:15:14.100000
 And there we are.

0:15:14.100000 --> 0:15:17.580000
 So we can see that in this particular
 database called users, we have the

0:15:17.580000 --> 0:15:19.040000
 following collections.

0:15:19.040000 --> 0:15:20.940000
 We have banned current and passed.

0:15:20.940000 --> 0:15:22.580000
 All right. So this makes sense.

0:15:22.580000 --> 0:15:27.860000
 This particular database looks like
 it's storing user information.

0:15:27.860000 --> 0:15:32.440000
 And within the database, we have collections
 or tables that will probably

0:15:32.440000 --> 0:15:35.720000
 have banned users, current
 users and past users.

0:15:35.720000 --> 0:15:40.800000
 Right. So let's go through
 some practical examples.

0:15:40.800000 --> 0:15:43.920000
 And I'm going to, you know, of course,
 this particular lab will have a

0:15:43.920000 --> 0:15:46.080000
 set of questions and I'm going
 to help you answer them.

0:15:46.080000 --> 0:15:51.040000
 So the first question is, you know, how
 we can find information, you know,

0:15:51.040000 --> 0:15:54.640000
 so what I'm going to do
 is I'll say show DBS.

0:15:54.640000 --> 0:15:57.860000
 And you can see we have a
 database called flag here.

0:15:57.860000 --> 0:15:59.660000
 So I'm going to say use flag.

0:15:59.660000 --> 0:16:06.360000
 And we can say show collections
 in this particular database.

0:16:06.360000 --> 0:16:11.180000
 And now what we can do is if we wanted
 to find, you know, the value of

0:16:11.180000 --> 0:16:16.380000
 a flag from within that particular,
 from this particular collection, as

0:16:16.380000 --> 0:16:19.840000
 it were, or from this
 particular database.

0:16:19.840000 --> 0:16:25.280000
 And collection, what we could do is
 say, you know, db.flag, sorry, db

0:16:25.280000 --> 0:16:28.340000
.flag. And then we say find, all right.

0:16:28.340000 --> 0:16:32.740000
 So put in a two or put
 in your brackets here.

0:16:32.740000 --> 0:16:38.880000
 We hit enter. And what is going to
 do is it's going to find the value

0:16:38.880000 --> 0:16:42.900000
 of the flag that, you know, obtained
 from the MongoDB cluster.

0:16:42.900000 --> 0:16:47.380000
 All right. Now we can switch into
 that particular collection.

0:16:47.380000 --> 0:16:52.820000
 And, you know, for example, in this case,
 we're just using the query language,

0:16:52.820000 --> 0:16:55.060000
 the Mongo query language
 here to find the flag.

0:16:55.060000 --> 0:16:59.420000
 But if we say, you know, show collections
 once more, show collections.

0:16:59.420000 --> 0:17:04.440000
 And we say, in this case,
 let's see, use flag.

0:17:04.440000 --> 0:17:09.640000
 Or we can just, you know, in this case,
 you know, in order to view it,

0:17:09.640000 --> 0:17:13.120000
 we can just say db.flag and then
 display the actual flag.

0:17:13.120000 --> 0:17:15.340000
 So we say db.flag.

0:17:15.340000 --> 0:17:19.460000
 In this particular case, you can use
 the auto completion here to display

0:17:19.460000 --> 0:17:24.520000
 other commands. So for example, we
 can find which you've already done.

0:17:24.520000 --> 0:17:29.380000
 You can also aggregate count, et cetera.

0:17:29.380000 --> 0:17:30.900000
 Interesting commands we can run.

0:17:30.900000 --> 0:17:41.020000
 So if we go back to, we say, show dbs,
 if we go to the user's database,

0:17:41.020000 --> 0:17:45.840000
 and we, let's try and find
 a particular user, right?

0:17:45.840000 --> 0:17:52.800000
 In this particular case, the question
 is asking us to find a, to find

0:17:52.800000 --> 0:17:54.320000
 a particular user.

0:17:54.320000 --> 0:17:55.800000
 So for example, how would we do that?

0:17:55.800000 --> 0:18:00.780000
 So, you know, if we say show collections,
 we don't need to go into any

0:18:00.780000 --> 0:18:04.640000
 of them, but we could
 say db.current.find.

0:18:04.640000 --> 0:18:09.000000
 And then in brackets, we can open up
 brackets and then use curly braces

0:18:09.000000 --> 0:18:11.780000
 and say the user field.

0:18:11.780000 --> 0:18:16.120000
 What we want to do is find a particular
 user that matches, let's say,

0:18:16.120000 --> 0:18:21.840000
 Alexis, right? And we can enclose the
 curly braces here and hit enter.

0:18:21.840000 --> 0:18:25.240000
 Now it doesn't find a user called Alexis,
 but let's try another user.

0:18:25.240000 --> 0:18:29.780000
 And in this case, I can say, for example,
 find the user header, no match,

0:18:29.780000 --> 0:18:31.300000
 because this is case sensitive.

0:18:31.300000 --> 0:18:34.040000
 So let's try that with an upper case H.

0:18:34.040000 --> 0:18:39.220000
 There we are. So we're able to find
 a particular, we're able to find a

0:18:39.220000 --> 0:18:40.060000
 particular user.

0:18:40.060000 --> 0:18:45.340000
 Now let me walk you through how you can
 view, how you can view data stored

0:18:45.340000 --> 0:18:47.060000
 within collections.

0:18:47.060000 --> 0:18:52.300000
 So if you wanted to list, you know, the
 actual documents within a particular

0:18:52.300000 --> 0:18:55.820000
 collection, what you can do is again,
 let's start off from the beginning

0:18:55.820000 --> 0:19:00.540000
 show databases and let's say use
 the database called users.

0:19:00.540000 --> 0:19:02.600000
 And we say show collections here.

0:19:02.600000 --> 0:19:04.540000
 So I'm going to say show collections.

0:19:04.540000 --> 0:19:06.720000
 And we have, let's say,
 current ones, right?

0:19:06.720000 --> 0:19:11.240000
 So let's say db.users.find.

0:19:11.240000 --> 0:19:16.960000
 And then, sorry, let me type that
 incorrectly here, db.users.find.

0:19:16.960000 --> 0:19:24.120000
 In this particular case, there we are.

0:19:24.120000 --> 0:19:28.720000
 So this is the data stored within
 that particular collection, right?

0:19:28.720000 --> 0:19:33.860000
 Or the data stored within that particular,
 the documents, rather as it

0:19:33.860000 --> 0:19:35.980000
 was stored within that
 particular collection.

0:19:35.980000 --> 0:19:39.940000
 So in here, we can see now the individual
 data, which is key value.

0:19:39.940000 --> 0:19:42.100000
 And there's multiple fields here.

0:19:42.100000 --> 0:19:46.160000
 So, you know, if I was to zoom out
 and display this, so it's displayed

0:19:46.160000 --> 0:19:50.420000
 or rendered correctly, I can hit enter,
 you can see that we have the ID

0:19:50.420000 --> 0:19:56.160000
 object ID, and then the user, the actual
 name here, the join date, the

0:19:56.160000 --> 0:19:58.960000
 email, etc. So very similar
 to a relational database.

0:19:58.960000 --> 0:20:02.680000
 So I just want to go through that again,
 because it can be quite difficult

0:20:02.680000 --> 0:20:04.280000
 to understand the abstraction.

0:20:04.280000 --> 0:20:07.300000
 So we have databases, right?

0:20:07.300000 --> 0:20:11.540000
 Databases are just the same as they
 are in a relational database.

0:20:11.540000 --> 0:20:14.500000
 They store tables, or in this
 case, collections, all right?

0:20:14.500000 --> 0:20:20.660000
 So if we say, use a particular database
 like users, we can now say show

0:20:20.660000 --> 0:20:23.860000
 collections, the equivalent
 of saying show tables.

0:20:23.860000 --> 0:20:29.380000
 So show essentially in no SQL databases,
 collections are just tables,

0:20:29.380000 --> 0:20:34.620000
 right? And collections are a collection
 of documents, right?

0:20:34.620000 --> 0:20:38.220000
 And documents store, you know,
 specific data, right?

0:20:38.220000 --> 0:20:42.660000
 So for example, in this particular case,
 you know, if we wanted to find

0:20:42.660000 --> 0:20:45.700000
 out, for example, there's another,
 you know, command we can run.

0:20:45.700000 --> 0:20:49.100000
 So we can say, DB dot past or band users.


0:20:49.100000 --> 0:20:55.740000
 So we can say DB dot band dot find,
 and within say dot count to show,

0:20:55.740000 --> 0:21:00.800000
 you know, the total number of band users
 or entries within that particular,

0:21:00.800000 --> 0:21:04.880000
 within that particular collection, it'll
 show us the amount of documents.

0:21:04.880000 --> 0:21:06.300000
 So we'll let enter.

0:21:06.300000 --> 0:21:07.900000
 So they're 91 documents.

0:21:07.900000 --> 0:21:11.520000
 So a document in this case is what
 you typically consider a record.

0:21:11.520000 --> 0:21:15.660000
 So if we go back to the previous command
 here, where we listed out the,

0:21:15.660000 --> 0:21:22.800000
 the current, the actual content of
 the current collection, you can see

0:21:22.800000 --> 0:21:27.280000
 that these here are all entries, but
 they're all individual documents.

0:21:27.280000 --> 0:21:37.360000
 All right, so for every user here, these
 are all storing data is preferred.

0:21:37.360000 --> 0:21:42.860000
 Now, as I said, there's multiple
 types of queries we can perform.

0:21:42.860000 --> 0:21:47.680000
 And what we can do is let's say show
 collections, we can say, in this

0:21:47.680000 --> 0:21:54.040000
 particular case, DB dot, DB dot band
 dot find, let's see what users have

0:21:54.040000 --> 0:22:00.280000
 been banned, band dot find.

0:22:00.280000 --> 0:22:04.740000
 You can see these are all the band users
 here, and these are all documents.

0:22:04.740000 --> 0:22:08.120000
 So we can try and perform
 some additional queries.

0:22:08.120000 --> 0:22:11.720000
 You know, if we were interested in finding
 some particular information,

0:22:11.720000 --> 0:22:13.740000
 which I just showed you how to do.

0:22:13.740000 --> 0:22:20.680000
 So for example, if I said DB dot band
 dot find, I could in here put in

0:22:20.680000 --> 0:22:23.360000
 my query or the criteria, right?

0:22:23.360000 --> 0:22:29.040000
 So I would say for the field, for the
 field user, can you find a user

0:22:29.040000 --> 0:22:30.580000
 with the following value?

0:22:30.580000 --> 0:22:32.440000
 So we'll say user.

0:22:32.440000 --> 0:22:37.000000
 And this is where we got that criteria
 early on, we can say find a user

0:22:37.000000 --> 0:22:39.520000
 called Mona, which I know exists.

0:22:39.520000 --> 0:22:41.280000
 And we just hit enter.

0:22:41.280000 --> 0:22:41.800000
 And there we are.

0:22:41.800000 --> 0:22:44.700000
 So it's going to give us that
 particular document, right?

0:22:44.700000 --> 0:22:49.860000
 And again, you can do this for any
 of the, for any of the fields here.

0:22:49.860000 --> 0:22:56.200000
 So for example, we could again, search
 for emails or phone numbers, so

0:22:56.200000 --> 0:22:57.500000
 on and so forth.

0:22:57.500000 --> 0:23:00.980000
 And based on this, you can see how this
 is, how this is useful, because

0:23:00.980000 --> 0:23:04.920000
 this simple query can, you know, find
 data and then it refers to the actual

0:23:04.920000 --> 0:23:08.280000
 document storing the data and also lists
 out the data within the document,

0:23:08.280000 --> 0:23:10.080000
 right? So pretty cool.

0:23:10.080000 --> 0:23:15.440000
 So again, we can change that to something
 like, for example, we said,

0:23:15.440000 --> 0:23:19.340000
 hmm, let's see phone.

0:23:19.340000 --> 0:23:22.080000
 Or let's try, yeah, let's use phone.

0:23:22.080000 --> 0:23:25.040000
 And you know, in this case, we
 put in our own phone number.

0:23:25.040000 --> 0:23:28.920000
 So let's say someone was trying to log
 in, a better option might be their

0:23:28.920000 --> 0:23:33.500000
 email. The query would be something that
 checks for this particular value

0:23:33.500000 --> 0:23:39.360000
 within the current user collection,
 not the band one, but there we are.

0:23:39.360000 --> 0:23:44.960000
 So you know, we can say,
 Alexis at i Knee.com.

0:23:44.960000 --> 0:23:47.520000
 And let me type that in correctly here.

0:23:47.520000 --> 0:23:51.460000
 And I'll just zoom out, because this
 is too zoomed in, hit enter, so it

0:23:51.460000 --> 0:23:53.080000
 doesn't find anything.

0:23:53.080000 --> 0:23:57.180000
 Now, I've already shown you how to,
 you know, identify the, so if I say

0:23:57.180000 --> 0:24:03.920000
 DB dot band, DB dot band dot count,
 that's to tell the total number of

0:24:03.920000 --> 0:24:07.540000
 records or in the case of a new SQL database,
 the total number of documents

0:24:07.540000 --> 0:24:15.020000
 within a particular collection, 91,
 if we say DB dot current, we can see

0:24:15.020000 --> 0:24:18.940000
 the current users or the documents
 within that collection.

0:24:18.940000 --> 0:24:20.300000
 So very, very simple to understand.

