SQL for Hackers: Learn SQL Injection and Database Security for Penetration Testing

Поділитися
Вставка

КОМЕНТАРІ • 47

  • @killer123335
    @killer123335 Рік тому +8

    This is great work! Appreciate you doing this. We need more creators that show practical applications of tools, techniques and tactics instead of simply discussing theory.

    • @yanivhoffman
      @yanivhoffman  Рік тому +1

      Thanks so much for the kind words 🙏

  • @marinob7433
    @marinob7433 Рік тому +3

    Yaniv thank you for this video! Stunning video! Always on point! OTW has the touch of Midas when he explain things.

    • @yanivhoffman
      @yanivhoffman  Рік тому +1

      Thx a lot my friend . How are you ?

    • @marinob7433
      @marinob7433 Рік тому +1

      @@yanivhoffman Everything is fine , how are you?

    • @yanivhoffman
      @yanivhoffman  Рік тому

      @@marinob7433 I’m great!

  • @CactusJack182
    @CactusJack182 7 місяців тому +1

    Thanks otw for this course ❤

  • @spfd_
    @spfd_ Рік тому +1

    Thanks for another post Yaniv your a great guy and all of us really appreciate what you do! Make sure to take breaks so you don't get burnt out! WE LOVE YOUR VIDEOS

  • @happyeverafter1797
    @happyeverafter1797 10 місяців тому +2

    ​ @yanivhoffman ?Hackers-arise website no longer active?

    • @yanivhoffman
      @yanivhoffman  10 місяців тому +1

      They switched to new site hackers-arise.net

  • @AmrElsadek-rt1ip
    @AmrElsadek-rt1ip Рік тому +5

    Is there's another video coming for advanced SQL injection ?🤔

    • @yanivhoffman
      @yanivhoffman  Рік тому +1

      Yes we are planning as we wanted first to see the viewers feedbacks on this one

  • @idohoffmanfc3968
    @idohoffmanfc3968 Рік тому +3

    Super Interesting !!! Thx a lot

  • @BufferTheHutt
    @BufferTheHutt 9 місяців тому +2

    very interesting.
    Do you plan to record a video with OTW about RTL-SDR hacking?
    Or about radio signals in general

    • @yanivhoffman
      @yanivhoffman  9 місяців тому +1

      We did here is the link ua-cam.com/video/7z5SNEEyCfo/v-deo.htmlsi=iI0N0vaj6Jqbx7FF

    • @BufferTheHutt
      @BufferTheHutt 9 місяців тому

      @@yanivhoffman thanks.

  • @AmlakNila
    @AmlakNila 10 місяців тому

    This was really helpful for me, thank you

  • @Free.Education786
    @Free.Education786 11 місяців тому +2

    Please make beginner to advance level practical live website hacking, live website bug hunting, live website penetration testing, live website exploitation content video series...
    🙏 😊 💯✌❤💚💙💜😍😘🤝

  • @taiquangong9912
    @taiquangong9912 Рік тому +1

    After the basics what area should be focused on?

    • @yanivhoffman
      @yanivhoffman  Рік тому

      Depends on your goals. to become master hacker you need to be an expert in OS, Networking and Cybersecurity. in cyber there are many paths, so let me know your thoughts and i will guide you to the best of my knowledge

  • @hichemsavastano4430
    @hichemsavastano4430 Місяць тому +1

    What about upload shell most of the DBS don't let u to upload ¿

    • @yanivhoffman
      @yanivhoffman  18 днів тому

      Great question! You're absolutely right-most modern database systems are configured with strict permissions and security measures that prevent uploading files directly to the database server. However, in certain scenarios, attackers may exploit vulnerabilities to achieve similar outcomes.
      Here’s how:
      Leveraging SQL Injection for File Writing:
      If the database user has file permissions and the database server is on the same system as the web server, attackers might use SQL injection to write a malicious file (e.g., a web shell) into a directory accessible by the web server. For example:
      INTO OUTFILE '/var/www/html/shell.php'
      This is rare in well-secured environments since DBAs usually restrict these permissions.
      Second-Stage Exploits:
      Even if file uploading isn't possible, SQL injection can sometimes be used to gain further access (e.g., retrieving sensitive data or executing commands via stored procedures) and move laterally within the environment.
      Understanding Upload Limitations:
      Modern databases and web applications often implement measures like parameterized queries, WAFs (Web Application Firewalls), and file validation to block such attacks. This is why it’s important for security teams to enforce least privilege and harden configurations.

  • @Jarling-so4oi
    @Jarling-so4oi 2 місяці тому +2

    more OTW free mini courses?

  • @sinceinfinity3207
    @sinceinfinity3207 Рік тому +2

    GREAT!

  • @GamesOfficialYouTube
    @GamesOfficialYouTube Рік тому +1

    Sql injection brings memories😂 More videos like this❤

    • @yanivhoffman
      @yanivhoffman  Рік тому +1

      Coming soon (actually next week on hunting malware ) with hands on demo

  • @HAMADHamad-u7c
    @HAMADHamad-u7c Рік тому +2

    Can you add translation please ❤

  • @privetprivet9130
    @privetprivet9130 Рік тому +1

    סרטון מטורף

    • @yanivhoffman
      @yanivhoffman  Рік тому +1

      תודה רבה ❤️ תשתף בבקשה אם אתה יכול זה יעזור

  • @sqfdjgslkfdjgs
    @sqfdjgslkfdjgs Рік тому

    I think that this video should be titled as SQLite, or Basic SQL queries and not SQL Injection.

    • @yanivhoffman
      @yanivhoffman  Рік тому

      Thx for the comment. i actually agree and will modify

  • @impostorsyndrome1350
    @impostorsyndrome1350 3 місяці тому

    this channel is David Bombal-

    • @yanivhoffman
      @yanivhoffman  3 місяці тому

      I disagree, check out the content. Yet and im proud of it, im the second channel after David that works continuously with OTW. nothing wrong with that and many times not same subject as well.

    • @impostorsyndrome1350
      @impostorsyndrome1350 3 місяці тому +1

      @@yanivhoffman I was joking, all good. I understand you are you and David is David.

    • @yanivhoffman
      @yanivhoffman  3 місяці тому

      @@impostorsyndrome1350 hahaha all ok. David is great but indeed I’m am who I am. I try to make my own stuff.

  • @Crazy--Clown
    @Crazy--Clown Рік тому

    Jeff knows his shit

  • @BrittRuscher-y4p
    @BrittRuscher-y4p 3 місяці тому

    Bradtke Mill

  • @nowgamertv4148
    @nowgamertv4148 Рік тому +2

    круто