SQL Injection Hacking Tutorial (Beginner to Advanced)

Поділитися
Вставка
  • Опубліковано 4 лют 2025

КОМЕНТАРІ •

  • @davidbombal
    @davidbombal  Рік тому +76

    Learn SQL injection with Rana! Today's video demonstrates three SQL Injection attacks. Her course covers many more (9 hours of content) and you can get free access using the link below.
    // Labs, scripts and documents //
    Slides: github.com/rkhal101/Presentations/blob/main/2023/David-Bombal's-Channel/SQL%20Injection%20Video%20with%20David%20Bombal.pdf
    Lab #1 Link: portswigger.net/web-security/sql-injection/lab-login-bypass
    Lab #2 Link: portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-data-from-other-tables
    Lab #3 Link: portswigger.net/web-security/sql-injection/blind/lab-conditional-responses
    Lab #3 Python Script: github.com/rkhal101/Web-Security-Academy-Series/blob/main/sql-injection/lab-11/sqli-lab-11.py
    // Course options //
    You have multiple options:
    1) UA-cam: Free to watch: ua-cam.com/video/1nJgupaUPEQ/v-deo.html
    2) Udemy: www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?referralCode=922314AD50A8EF6BB043
    3) Rana's Academy: 50% OFF Coupon Code: "DavidBombal500FF" academy.ranakhalil.com/
    Rana explains the differences in this video: ua-cam.com/video/tuxukQ4gKOU/v-deo.html
    // Real World Example //
    OTW shows SQL Injection the real world: ua-cam.com/video/R1amgARgFDs/v-deo.html
    // Book Rana Recommended //
    Web Application’s Hacker’s handbook 2nd Ed by Dafydd Stuttard
    US Link: amzn.to/3J90wZa
    UK Link: amzn.to/3J7H2UT
    // Rana's SOCIAL //
    Twitter: twitter.com/rana__khalil
    Academy: academy.ranakhalil.com/
    UA-cam Channel: ua-cam.com/users/RanaKhalil101
    Medium Blog: ranakhalil101.medium.com/
    Rana Intigriti Interview: ua-cam.com/video/stXkOBZsNYo/v-deo.html&ab_channel=intigriti
    // David's SOCIAL //
    Discord: discord.gg/davidbombal
    Twitter: twitter.com/davidbombal
    Instagram: instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    // MY STUFF //
    www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
    // TIMESTAMPS //
    00:00 Coming up
    00:35 Disclaimer
    00:40 Intro
    01:00 Rana's first course
    01:53 Rana's platforms
    03:12 Support
    04:00 SQL injection overview
    05:05 SQL injection theory
    09:15 Rana's background
    10:19 SQL explanation
    11:46 Presentation
    13:10 1st lab
    16:48 Discussion about practical Labs
    17:57 Different types of SQL injection
    21:41 2nd lab
    32:14 Discussion about teaching
    33:04 3rd lab
    48:22 Discussion about labs
    48:54 Password lockout
    50:19 Cookie
    51:29 3rd lab conclusion
    51:49 Preventing SQL injection
    57:57 Course information
    58:34 SQL and developers
    59:27 Course progression
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.

    • @catarctic
      @catarctic Рік тому

      Thanks David!
      The Udemy link doesn't work, regardless it's a giveaway.

    • @davidbombal
      @davidbombal  Рік тому +4

      @@catarcticThe course is free on UA-cam. But, because some people prefer Udemy, here are 1,000 free places to Rana's course (first 1,000 get the course for free): www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?couponCode=AC321B423BA301178A56

    • @cybersecuritycs8129
      @cybersecuritycs8129 Рік тому

      hy david iam in pakistan and i really like your content can you please give the udemy course for free plz

    • @shahariarking3850
      @shahariarking3850 Рік тому

      ​@@davidbombalsir this link is not working...

    • @davidbombal
      @davidbombal  Рік тому

      @@shahariarking3850 Try again .... fixed...

  • @RanaKhalil101
    @RanaKhalil101 Рік тому +505

    Thank you for having me on your channel David! I'm very excited about this collaboration 😃

    • @hackerzoon101
      @hackerzoon101 Рік тому +21

      ZazakAllahu Kahir sister Rana
      Support and Prayer for you from Bangladesh 🇧🇩💐

    • @hackerzoon101
      @hackerzoon101 Рік тому +8

      Stay blessed and keep making progress

    • @SweetOrchardFarms
      @SweetOrchardFarms Рік тому +4

      Thank you so much, Rana! You're awesome! Keep killing it :)

    • @RoomTwentyNine
      @RoomTwentyNine Рік тому +4

      Thank you so much Rana

    • @davidbombal
      @davidbombal  Рік тому +19

      So happy to be collaborating with you Rana! Thank you for everything you do for the community!

  • @hackerzoon101
    @hackerzoon101 Рік тому +20

    MashAllah ما شاء الله
    Thank you sister Rana for the beautiful gif ZazakAllahu Kahir.
    Support for her from Bangladesh 🇧🇩💐

  • @theMadhatter817
    @theMadhatter817 Рік тому +51

    This is gold! The way she explains everything is amazing. Makes it super simple and easy to follow. Definitely going to check out her full 9hr course.

  • @davidbombal
    @davidbombal  Рік тому +34

    Because some people prefer Udemy, here are 1,000 free places to Rana's course (first 1,000 get the course for free): www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?couponCode=AC321B423BA301178A56

    • @mistacoolie8481
      @mistacoolie8481 Рік тому +1

      Thank you both for this great resource. I have been on this journey for a Little and every thing I can learn from this high level technical will help me to move forward. Thank you again . 🎉

    • @davidbombal
      @davidbombal  Рік тому +5

      Please reply here if you got the course for free!
      If you didn't get it in time, you can watch the course for free on UA-cam here: ua-cam.com/video/1nJgupaUPEQ/v-deo.html

    • @Ganesh-lq7op
      @Ganesh-lq7op Рік тому

      Thank you sir ❤

    • @shahariarking3850
      @shahariarking3850 Рік тому

      ​@@davidbombalthank you sir and Rana this link working properly....

    • @ronaldmacheka2180
      @ronaldmacheka2180 Рік тому

      @@davidbombal got the course thank you

  • @pregesor
    @pregesor Рік тому +20

    You are One of the Best Teacher in UA-cam 🤗

  • @LoneWolf5960
    @LoneWolf5960 Рік тому +10

    Convenient timing. I'm starting my first bug bounty with a VDP with the Dept. of State. I'm in the Recon stage but based on the progression it's possible I'd probably need a XSS or SQLi to find a bug. I already brought a short but practical course for XSS and now there's this recommended by the UA-camr who helped me get my CCNA via his Udemy Course, I know I can expect good training content.
    Good luck to everyone in the comments.

    • @davidbombal
      @davidbombal  Рік тому +4

      Great :) Rana's content is amazing. Port Swigger even wanted to buy her content :)

  • @ramseshernandez3725
    @ramseshernandez3725 Рік тому +1

    Waooooo, was great to watch this video, thanks for share other level to learn sql injection; Thanks David and Rana 👍,

  • @YoursTrulyRob
    @YoursTrulyRob Рік тому +16

    9 hours Christmas came early. This Weeknd is going to be fun 🎉 Thank you sir for always coming through

  • @bhavanisankar7422
    @bhavanisankar7422 Рік тому +5

    Thanks david and Rana Khalil for this amazing course. Really i am very thankfull to both of you . Lots of love from india

  • @renn3014
    @renn3014 Рік тому +11

    This is awesome !!! I also love that Rana is a woman in this space and a Hijabi woman !! 🙌 it’s great to see, this is my 1st time swing this. Great content David yet again ! Thank you! This channel has alerted me to recent cyber threat methods, taught me so much and has also pointed me in the direction of great learning resources (books, labs, videos, teachers) and it’s super useful especially considering I’m a beginner in cyber security . Thanks ☺️

  • @SweetOrchardFarms
    @SweetOrchardFarms Рік тому +1

    Thank you so much, guys! I love your channel, David!

  • @Mr_H.AK-47
    @Mr_H.AK-47 Рік тому +6

    I LOVE YOU DAVIDDD. you always post great videos and explain it in such a way that's mesmerizing. I turned 17 this 13th of july and i have been watching your videos from the age of 13 . i really appreciate your content. you have given me soo much motivation and inspiration and have inspired me to choose cyber security as a career later in life. LOVE FROM PAKISTAN SIRR🥰🥰

  • @AToneForOurSins
    @AToneForOurSins 6 місяців тому

    She makes it so easy to comprehend. What an incredible and well spoken instructor. 👏

  • @scott8964
    @scott8964 Рік тому +1

    God bless you both love to see more people helping others

  • @RusselChakauya
    @RusselChakauya 6 місяців тому

    Hey, there , just wanna say thanks for such great content and a wide variety of topics, really helpful
    Love from South Africa 🇿🇦

  • @mere_naina
    @mere_naina Рік тому +7

    She's really great and talented expert. Very helpful video😊

  • @ryanten6475
    @ryanten6475 Рік тому +2

    absolutely love her ❤❤❤❤

  • @superdupercorp
    @superdupercorp Рік тому +1

    im on a reskilling for employment type of programme and, instead of having my actual TEACHER do his job and explain this himself, he told us to follow this hour-long tutorial. no shade to you, mr. david, im just frustrated with the lack of preparation im getting if i am to get a job in this field.

  • @geniustic1541
    @geniustic1541 Рік тому

    Thank you for making the course available on UA-cam, both you guys! God bless

  • @the_yugandharr
    @the_yugandharr 9 місяців тому +1

    very well explained by Rana

  • @toluwajoe5680
    @toluwajoe5680 Рік тому +2

    This is so profound, even for a learner. I've got an observation and a question, One would need the reconnaissance skill to fins out some details of the web app, like the username of the admin and other registered users, also, would like to know how to use burpe suite to create such proxy and connect the website we working on.
    is it okay to show few tips of those before diving into the sql injection proper?
    Thank you

  • @AadiLAit
    @AadiLAit Рік тому

    David B.
    Thanks lot man, This is one of your best Videos. This is so helpful with awesome information from Rana. Iam watching this video for 3rd time now.
    Thank you

  • @txfalkon2882
    @txfalkon2882 Рік тому

    Good to see you back Rana. Great seeing you back is awesome. you in the security field I believe is one great encouragement to ladies out there to as well join the security field. awesome. Thanks David as well.

  • @sidalexis
    @sidalexis Рік тому +5

    Took this course on Udemy yesterday
    Just one piece of feedback: The font on VS code needs to be a bit larger 😊

  • @Patriotic8422
    @Patriotic8422 Рік тому +1

    *Very informative and useful fr me* 🙏

  • @general.commander.1
    @general.commander.1 Рік тому

    شكرا الاستاذ ديفيد على المعلومات التى تنشرها لنا لك التحية من مصر

  • @olumideajose2162
    @olumideajose2162 Рік тому

    just snagged it on udemy, You guyz are amazing. Stay Blessed

  • @naadiaheimers1705
    @naadiaheimers1705 Рік тому

    its been 11 years since someone teached me sql injection, and i never get bored

  • @AbdAlkarimTube
    @AbdAlkarimTube Рік тому

    Great video, We need more from Rana! Thanks.

  • @joshuadughi
    @joshuadughi Рік тому

    Great content, Again!!
    Thank you, David! Thank you, Rana!

  • @mfahad710
    @mfahad710 Рік тому

    Amazing Stuff
    Rana Khalil

  • @demotedc0der
    @demotedc0der Рік тому

    everything explained very clear,,, such a great content david ''' we need more like this

  • @vikk98
    @vikk98 Рік тому

    love from village (India) i most watch your video alway awesome

  • @meta-zeno505
    @meta-zeno505 Рік тому

    I missed my last chance, not missing this one!!!!! Plus I love SQL work!!!!

    • @davidbombal
      @davidbombal  Рік тому

      The course is free on UA-cam, so no rush :)

    • @meta-zeno505
      @meta-zeno505 Рік тому

      Awsome, thanks David.
      Since February I have devoted myself 5 days a week for 8 hours of learning and educating myself with tryhackme, videos you have published to put me at a level where I can break into the industry, although not successful yet, it has opened my eyes to how vulnerable we really are!! Scary stuff lol😂

  • @gulshanyadav3140
    @gulshanyadav3140 Рік тому

    Thank you very much David and Rana!!

  • @adewolekayode6148
    @adewolekayode6148 Рік тому

    This is very interesting. God bless you more ..❤

  • @hackerzoon101
    @hackerzoon101 Рік тому

    David your doing great, bring intalactuls along side with recourses and lab
    I appreciate for your kind affort brother

  • @jb-spaceworld2069
    @jb-spaceworld2069 Рік тому

    Absolutely brilliant stuff David! Where did you find this amazing legend? Rana, thank you so much.....am totally in!

  • @ariasm8911
    @ariasm8911 Рік тому

    this give me goosebump, great content

  • @bekame4548
    @bekame4548 Рік тому

    Thank you David ,good job Rana 👍

  • @royalonlineboy
    @royalonlineboy Рік тому

    I love the way she explains things.

  • @mohamedamrani4853
    @mohamedamrani4853 Рік тому

    God bless you sister rana

  • @xwinglover
    @xwinglover Рік тому

    What a great presentation

  • @DevakiNandhan
    @DevakiNandhan Рік тому +1

    Ya..???? This is best course in UA-cam @Rana

  • @z0nerider
    @z0nerider Рік тому

    Awesome work @rana and great content @david as usual !! Loved the mathematics joke btw 😀

  • @colton923
    @colton923 Рік тому

    What a perfect new subject to learn.

  • @ElevenOO1
    @ElevenOO1 Рік тому

    Great collection

  • @AWhite_
    @AWhite_ Рік тому

    Great Course, thank you so much.

  • @kimutaifelix9092
    @kimutaifelix9092 Рік тому

    She's Good 👏👏👏💪

  • @xRiPw0lFx
    @xRiPw0lFx Рік тому

    Love seeing intelligent women well-versed in cybersecurity 😉😉😁😁

  • @SabonaMarara
    @SabonaMarara Рік тому

    wow great video!

  • @alisenjary
    @alisenjary Рік тому

    Thanks David and rana ❤❤

  • @mariusgjura-beluga
    @mariusgjura-beluga Рік тому

    Thank you so much . I have already shut down and deleted over 20 government websites on my country

  • @DaniMHMDI
    @DaniMHMDI Рік тому +1

    Great as always 👑

  • @mmuhamme2001
    @mmuhamme2001 Рік тому

    Love your content ❤

  • @dffhhfhdifh
    @dffhhfhdifh Рік тому

    Thankyou so much great tutorial leart alot😊❤

  • @catarctic
    @catarctic Рік тому +1

    Wow, looks amazing content!
    Many cheers to David and Rana!
    And I like her voice too.
    Is the Udemy course a giveaway too? Because it doesn't look alike by the link provided.
    Happy weekend to you!

    • @davidbombal
      @davidbombal  Рік тому

      Hint... Look for for my comment :)

    • @catarctic
      @catarctic Рік тому +1

      @@davidbombal Oh sorry, I was searching for my glasses everywhere, but they were tilted up on my head 😉
      Anyway, all the above still applies!
      Thanks for these fantastic collaborations, may them be to your growth as well!

    • @davidbombal
      @davidbombal  Рік тому

      @@catarctic You have time to get it... refresh the page and look for my comment :)

    • @catarctic
      @catarctic Рік тому

      @@davidbombal Nuh, I just tried to refer that at the time of writing your comment link didn't appeared yet on my side haha, that's why I searched blindly

  • @hardeepsingh_07
    @hardeepsingh_07 Рік тому +1

    Thank again I wating for this ❤

  • @CarKeyGuyNL
    @CarKeyGuyNL Рік тому

    Realy good content!
    the onlyy thing is the background of Ranal video... if i look at the coding, she get blured and all i see is a funny flying head..

  • @micah6465
    @micah6465 Рік тому

    Danggg what an excellent teacher 😅

  • @cataclysmicproductions
    @cataclysmicproductions 3 місяці тому

    imagine having her in the office, Great personality

  • @arashautomationlab9088
    @arashautomationlab9088 Рік тому

    Thank you sister
    الحمدالله

  • @McduduTQ
    @McduduTQ Рік тому

    8 +HOURS OF LAB....SWEET

  • @vilma-lima5295
    @vilma-lima5295 Рік тому

    top,,, i like very good

  • @kentapostol6909
    @kentapostol6909 Рік тому

    Great ❤

  • @muhon19
    @muhon19 Рік тому

    Masha allha good see you sisters

  • @affulsamuel728
    @affulsamuel728 Рік тому

    i love your videos

  • @Rbx_Corrupted
    @Rbx_Corrupted Рік тому

    thank you very much ❤❤❤

  • @hardyosman7922
    @hardyosman7922 5 місяців тому

    RANA BEST TECHER

  • @PhilosophyEpochs
    @PhilosophyEpochs Рік тому

    thank you david SIR !

    • @davidbombal
      @davidbombal  Рік тому

      You're welcome! Rana is amazing and we can learn so much from her!

  • @ekwuruibemarshalnnamdi9239
    @ekwuruibemarshalnnamdi9239 Рік тому

    Thank you David

  • @AadiLAit
    @AadiLAit Рік тому

    Perfect Demos for new learners :-)

  • @w3sp
    @w3sp Рік тому

    Great video.
    Dumb question:
    Does that '-- exploit only work if there are no line breaks in an SQL?

  • @nunoalexandre6408
    @nunoalexandre6408 Рік тому

    Love it!!!!!!!!!!!!!!!!!!!!!

  • @KProjects-qo5ix
    @KProjects-qo5ix Рік тому

    Love it 😌...kinda new to this tho

  • @NardusVanStaden
    @NardusVanStaden Рік тому

    I was like....whaaaat, this woman looks like an innocent housewife, would never expect this from her...hahaha nicely done

  • @sebitguado2058
    @sebitguado2058 Рік тому

    Thank you boss❤❤❤

    • @davidbombal
      @davidbombal  Рік тому +1

      Thank you! I'm just trying to help as many people as I can :)

  • @CYBER-HERO
    @CYBER-HERO Рік тому +1

    Hello Mr. Bombal i wanna ask a question if you don't mind. How long you were in IT and cybersecurity and if you got something to say for a 17 years old geek can you tell.

  • @RIPscammers
    @RIPscammers Рік тому +1

    Hey david, do you know what is happening in India in the Manipur case

  • @Engsfscrypto
    @Engsfscrypto Рік тому

    @david bombal really you are amazing 🎉🎉🎉🎉🎉 I Support you ,go forward , keep going you have great job 👏 to help and support the people around intee world bro 👊

  • @TonyFarley-gi2cv
    @TonyFarley-gi2cv Рік тому

    Don't be afraid to say we like your backing until we get up and going but we don't want you as a takeover in it we want you to help us show us the correct way to develop

  • @Mariusmiglia
    @Mariusmiglia Рік тому

    David thank you so much for your work! I love your program. I'm about to buy the book of Occupy the Web "Getting Started Becoming a Master Hacker" but I have a doubt, 'cause I want to know if this book is updated. Could you please tell what you think? thank you again. You are amazing

  • @camelotenglishtuition6394
    @camelotenglishtuition6394 Рік тому

    Fantastic!

    • @davidbombal
      @davidbombal  Рік тому +1

      Glad you like it! Enjoy the course!

    • @camelotenglishtuition6394
      @camelotenglishtuition6394 Рік тому

      @davidbombal thank you .. I'm just working through blackhat api but will jump on this at some point

  • @affulsamuel728
    @affulsamuel728 Рік тому

    professor when you interview them and i watch, it seem like the same method i use but i dont find vulns only i tried brute forcing before i gain access and use cred to connect to protocols so please let them tell the magic they use in real world because it seems like studies. please i love your channel soo much thank you professor

  • @THRE3KINGZStudios3kz
    @THRE3KINGZStudios3kz Рік тому

    Needed this!

    • @davidbombal
      @davidbombal  Рік тому +1

      Hope the course helps you! Rana has lots of fantastic content on her channel - even more than this!

  • @AhmedAli5530
    @AhmedAli5530 Рік тому +3

    As most of the developers use prepared statements, do you think there is still chance of sql injection, as most of the modern frameworks have sql inject prevention built into the security components?

    • @davidbombal
      @davidbombal  Рік тому +1

      The recent hack of MOVEit shows that unfortunately hackers can still use SQL Injection to gain access. Watch this video for details: ua-cam.com/video/R1amgARgFDs/v-deo.html

  • @ahmadmikati3397
    @ahmadmikati3397 Рік тому

    @ranakhalil101, we are super proud of you! Well done!

  • @my-rules
    @my-rules Рік тому

    Thanks a lot

  • @ahmedtalaat27
    @ahmedtalaat27 Рік тому

    You are both always have a very good content

  • @barkhadibraahim1023
    @barkhadibraahim1023 Рік тому

    great video

  • @FruchtDesZorns
    @FruchtDesZorns Рік тому

    Wow, I'm your next student

  • @mynameiskranz
    @mynameiskranz Рік тому

    method POST is more saver, right?

  • @borhen-di6ik
    @borhen-di6ik Рік тому

    Hello David, can You make a video about Cyber Security, Thanks

  • @knvsf2829
    @knvsf2829 Рік тому

    I’m diving to this

  • @marciodias778
    @marciodias778 Рік тому +1

    Excelente video, mas poderia ter tradução para português Brasil, por favor!

  • @73dines
    @73dines Рік тому

    Rana is the real life Trenton from Mr Robot. ☺

  • @MrPlayboy-d2o
    @MrPlayboy-d2o Рік тому

    How does this password bruteforce initially work? It guesses each character based on what?

  • @yvng4697
    @yvng4697 Рік тому

    Mashallah

  • @UCcdTp7XpCkVLkaRCsDcifFg
    @UCcdTp7XpCkVLkaRCsDcifFg 5 місяців тому

    realy beauty