What is SQL Injection Attack

Поділитися
Вставка
  • Опубліковано 11 січ 2025

КОМЕНТАРІ • 46

  • @cagatay7201
    @cagatay7201 7 років тому +4

    awesome awesome awesome as always

    • @Csharp-video-tutorialsBlogspot
      @Csharp-video-tutorialsBlogspot  7 років тому +2

      Thank you very much for taking time to give feedback. This means a lot. I am very glad you found the videos useful.
      I have organised all the Dot Net & SQL Server videos in to playlists, which could be useful to you
      ua-cam.com/users/kudvenkatplaylists?view=1&sort=dd
      If you need DVDs or to download all the videos for offline viewing please visit
      www.pragimtech.com/order.aspx
      Slides and Text Version of the videos can be found on my blog
      csharp-video-tutorials.blogspot.com
      Tips to effectively use my youtube channel.
      ua-cam.com/video/y780MwhY70s/v-deo.html
      If you want to receive email alerts, when new videos are uploaded, please subscribe to my youtube channel.
      ua-cam.com/users/kudvenkat
      If you like these videos, please click on the THUMBS UP button below the video.
      May I ask you for a favor. I want these tutorials to be helpful for as many people as possible. Please share the link with your friends and family who you think would also benefit from them.
      Good Luck
      Venkat

  • @Csharp-video-tutorialsBlogspot
    @Csharp-video-tutorialsBlogspot  11 років тому +6

    Hi, thank you very much for taking time to give feedback. I am very glad you found these videos useful. May I ask you for a favour. I am receiving lot of questions everyday from our youtube users, and finding it extremely difficult to answer all the questions in time. I hope, you can help me answer a few questions for which you know the answer. Hope you can help. Good Luck.

  • @Csharp-video-tutorialsBlogspot
    @Csharp-video-tutorialsBlogspot  11 років тому +1

    Hi, thank you very much for taking time to give feedback. I am very glad you found these videos useful. To receive email alerts, when new videos are uploaded, please subscribe to my youtube channel. May I ask you for a favour. I want these tutorials to be helpful for as many people as possible. Please share the link with your friends and family who you think would also benefit from them. If you like these videos, please click on the THUMBS UP button below the video.

  • @2elsteffo
    @2elsteffo 11 років тому +1

    This is one of the subjects where I have read and watched a whole lot of tutorials without really understanding much of it. When I see your tutorials, I understand it instantly. Wish I had come across your great videos earlier. Would have saved me an awful lot of time. Tnx

  • @Csharp-video-tutorialsBlogspot
    @Csharp-video-tutorialsBlogspot  11 років тому +1

    Thank you very much for taking time to give feedback. In the description of this video, I have included the link for ASP .NET, C#, and SQL Server playlists. All the videos are arranged in logical sequence in these playlists, which could be useful to you. Please share the link with your friends who you think would also benefit from them. If you like these videos, please click on the THUMBS UP button below the video. For email alerts, when new videos are uploaded, you may subscribe to my channel.

  • @Mr__B.
    @Mr__B. 2 роки тому

    Brilliant explanation as usual!
    Still relevant after so many years.

  • @SuperGojeto
    @SuperGojeto 9 років тому +3

    Finally i understood sql injection!! Kudos!!!

  • @Mrsswatisinha
    @Mrsswatisinha 11 років тому

    Great job. I had never thought of it(the SQL engine attack).
    I have watched your other videos and I must say that the way you explain things is very good. Keep up the good work. You are helping a lot of us out here.

  • @mohammadasrarulhoque429
    @mohammadasrarulhoque429 11 років тому

    Very much useful....I have learned SQL Server only by the help from your videos...

  • @senthilkumarraja5333
    @senthilkumarraja5333 3 роки тому

    Very good explanation for easily understanding the SQL injection

  • @shaulkobirkov407
    @shaulkobirkov407 2 роки тому

    Beautifully demonstrated, thank you!!!

  • @shenth27
    @shenth27 11 років тому +2

    Nice explanation of SQL Injection in simple terms. But just one concern that the stored procedure could still be vulnerable to sql injection, if the input parameter is concatanated with sql statement within the stored procedure.

  • @Csharp-video-tutorialsBlogspot
    @Csharp-video-tutorialsBlogspot  13 років тому +1

    This video is about Injecting SQL, when we build sql commands by concatenating user input. Of course, the video is about SQL injection. Let me know, that part that you are not clear about. By the way SQL Injection happens, when the ADO.NET code is poorly written.

  • @gabio7386
    @gabio7386 3 роки тому

    awesomely explained

  • @Game-vi6if
    @Game-vi6if 5 років тому +1

    Well SQL injection is very interesting.

  • @CursosIcarnegie
    @CursosIcarnegie 10 років тому

    Nice explanation!! Thank you. Regards Paco from Mexico

  • @HanNguyen-gz1oc
    @HanNguyen-gz1oc 9 років тому

    Awesome video! Thank you for sharing!

  • @rjangheldotcom204
    @rjangheldotcom204 5 років тому

    Superb. Thanks.

  • @zhalie12345
    @zhalie12345 11 років тому

    Nice explanation kudvenkat.. Thanks.. :D

  • @victorchorques4893
    @victorchorques4893 8 років тому

    Thank you very much! Very easy to understand (:

  • @arpitsaini084csc9
    @arpitsaini084csc9 3 місяці тому

    But i have a question
    you gave us a example of the query which the user can write to delete any data from the database
    but how he would know the exact name of table .

  • @sureshrajput5794
    @sureshrajput5794 9 років тому

    very well expalined sir u r great sir

  • @adamstearns3097
    @adamstearns3097 9 років тому

    Great video thank you

  • @durgaprasadtoram2911
    @durgaprasadtoram2911 11 років тому +1

    Nice video thank you

  • @aapkanigam
    @aapkanigam 11 років тому

    hello sir,
    how to store
    in sql using asp?
    i replaced
    with "br" but as i retrieve it with gridveiw it does not change the line.

  • @albahrainking
    @albahrainking 11 років тому

    Great lesson thanks very much

  • @ivandrofly
    @ivandrofly 11 років тому +2

    Which playlist this videos belongs to?

  • @giorgiteneishvili5262
    @giorgiteneishvili5262 10 років тому

    hi venkat thanks for this tutorials.
    question: where (typically) does the parameter replacement happen?
    when using sqlparameters.
    P.S. i'm already subbed and again thanks for this tutorials :)

  • @srinivasanjayamohan8177
    @srinivasanjayamohan8177 6 років тому

    Very useful thank you

  • @prvs8
    @prvs8 10 років тому

    very helpful. thanks.

  • @aminedavid6992
    @aminedavid6992 8 років тому

    thanks for your good explanation , but i have question how can i delete data from table (sql injection ) if i don't know the name of table?

  • @MrPrakash2111
    @MrPrakash2111 8 років тому

    Hello Venkat, You are just awesome...! :)
    Please do tutorial about ViewStateUserKey and CSRF
    thanks...!

  • @deepaksamala77
    @deepaksamala77 7 років тому

    Is string.format("select * from where id={0},''abc") and sql parameter both will avoid sqlinjection or only sqlparameterised will avoid sql injections

    • @AbhayThakur_Gallant_Knight
      @AbhayThakur_Gallant_Knight 6 років тому

      No, this won't stop SQL injection because with String.Format you are just replacing the text and not passing the value as a parameter.

  • @kowshikgullapudi5734
    @kowshikgullapudi5734 5 років тому

    please explain mail splitting in sql by using sub string

  • @deepaksamala77
    @deepaksamala77 7 років тому

    Concatinating string with Stored Procedure like "sp_getdetailswithid='"+txtid.text+'"; will it happen sql injection attack

  • @satyasubhashini7528
    @satyasubhashini7528 5 років тому

    Thankyou so much sir

  • @deepaksamala77
    @deepaksamala77 7 років тому

    if i use only "select col1, col2 from table1" without any parameters passing i will it fall into sql injection ,plz reply for my queries

  • @catalingabriel2959
    @catalingabriel2959 4 роки тому

    Thank you!

  • @raguramjeevan9314
    @raguramjeevan9314 7 років тому

    how does he know the table name or database name to delete

  • @bijayy33
    @bijayy33 7 років тому

    Thanks

  • @786gnafis
    @786gnafis Рік тому

  • @Csharp-video-tutorialsBlogspot
    @Csharp-video-tutorialsBlogspot  11 років тому +4

    Hi, thank you very much for taking time to give feedback. I am very glad you found these videos useful. To receive email alerts, when new videos are uploaded, please subscribe to my youtube channel. May I ask you for a favour. I want these tutorials to be helpful for as many people as possible. Please share the link with your friends and family who you think would also benefit from them. If you like these videos, please click on the THUMBS UP button below the video.

  • @Csharp-video-tutorialsBlogspot
    @Csharp-video-tutorialsBlogspot  11 років тому +1

    Thank you very much for taking time to give feedback. In the description of this video, I have included the link for ASP .NET, C#, and SQL Server playlists. All the videos are arranged in logical sequence in these playlists, which could be useful to you. Please share the link with your friends who you think would also benefit from them. If you like these videos, please click on the THUMBS UP button below the video. For email alerts, when new videos are uploaded, you may subscribe to my channel.