SQL injection - The oldschool way - 01
Вставка
- Опубліковано 8 лют 2025
- Welcome to the first tutorial of the "SQL Injection - The Old School Way" series!
In this video, we’ll lay the groundwork for discovering and exploiting SQL injection vulnerabilities. This hands-on session is perfect for anyone looking to understand the fundamentals of SQLi, from crafting queries to manipulating databases for data extraction.
Timestamps
00:00 Start
00:01 Intro that I should do
03:39 Differences between DBMSs
04:31 Select statement
06:03 Logical operations
09:50 Abusing data types
12:22 Abusing DB concatination
16:37 Abusing logical operations
18:43 MySQL comments
21:08 Why you shouldn't blindly depend on comments
23:36 Exploitins SQLi 101
24:24 Union
26:23 Order by
27:27 Exploitation and extracting data
35:14 What should you do next?
Challenge to solve is "SQL Injection: Breaking In - 01", and can be found at cyard.0x4148.com/
To download the docker image, use : github.com/0x4...
sqlfiddle I've used :
sqlfiddle.com/...
And
sqlfiddle.com/...
Facebook group for further discussions : / 2246549955562216 (State of security )
Author's social media channels:
/ xor.0x4148
x.com/0x4148