Learn SQL injection with Rana! Today's video demonstrates three SQL Injection attacks. Her course covers many more (9 hours of content) and you can get free access using the link below. // Labs, scripts and documents // Slides: github.com/rkhal101/Presentations/blob/main/2023/David-Bombal's-Channel/SQL%20Injection%20Video%20with%20David%20Bombal.pdf Lab #1 Link: portswigger.net/web-security/sql-injection/lab-login-bypass Lab #2 Link: portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-data-from-other-tables Lab #3 Link: portswigger.net/web-security/sql-injection/blind/lab-conditional-responses Lab #3 Python Script: github.com/rkhal101/Web-Security-Academy-Series/blob/main/sql-injection/lab-11/sqli-lab-11.py // Course options // You have multiple options: 1) RU-vid: Free to watch: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-1nJgupaUPEQ.html 2) Udemy: www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?referralCode=922314AD50A8EF6BB043 3) Rana's Academy: 50% OFF Coupon Code: "DavidBombal500FF" academy.ranakhalil.com/ Rana explains the differences in this video: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-tuxukQ4gKOU.html // Real World Example // OTW shows SQL Injection the real world: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-R1amgARgFDs.html // Book Rana Recommended // Web Application’s Hacker’s handbook 2nd Ed by Dafydd Stuttard US Link: amzn.to/3J90wZa UK Link: amzn.to/3J7H2UT // Rana's SOCIAL // Twitter: twitter.com/rana__khalil Academy: academy.ranakhalil.com/ RU-vid Channel: ru-vid.com Medium Blog: ranakhalil101.medium.com/ Rana Intigriti Interview: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-stXkOBZsNYo.html&ab_channel=intigriti // David's SOCIAL // Discord: discord.gg/davidbombal Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // TIMESTAMPS // 00:00 Coming up 00:35 Disclaimer 00:40 Intro 01:00 Rana's first course 01:53 Rana's platforms 03:12 Support 04:00 SQL injection overview 05:05 SQL injection theory 09:15 Rana's background 10:19 SQL explanation 11:46 Presentation 13:10 1st lab 16:48 Discussion about practical Labs 17:57 Different types of SQL injection 21:41 2nd lab 32:14 Discussion about teaching 33:04 3rd lab 48:22 Discussion about labs 48:54 Password lockout 50:19 Cookie 51:29 3rd lab conclusion 51:49 Preventing SQL injection 57:57 Course information 58:34 SQL and developers 59:27 Course progression Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only.
@@bistronautaThe course is free on RU-vid. But, because some people prefer Udemy, here are 1,000 free places to Rana's course (first 1,000 get the course for free): www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?couponCode=AC321B423BA301178A56
This is awesome !!! I also love that Rana is a woman in this space and a Hijabi woman !! 🙌 it’s great to see, this is my 1st time swing this. Great content David yet again ! Thank you! This channel has alerted me to recent cyber threat methods, taught me so much and has also pointed me in the direction of great learning resources (books, labs, videos, teachers) and it’s super useful especially considering I’m a beginner in cyber security . Thanks ☺️
Convenient timing. I'm starting my first bug bounty with a VDP with the Dept. of State. I'm in the Recon stage but based on the progression it's possible I'd probably need a XSS or SQLi to find a bug. I already brought a short but practical course for XSS and now there's this recommended by the RU-vidr who helped me get my CCNA via his Udemy Course, I know I can expect good training content. Good luck to everyone in the comments.
I LOVE YOU DAVIDDD. you always post great videos and explain it in such a way that's mesmerizing. I turned 17 this 13th of july and i have been watching your videos from the age of 13 . i really appreciate your content. you have given me soo much motivation and inspiration and have inspired me to choose cyber security as a career later in life. LOVE FROM PAKISTAN SIRR🥰🥰
im on a reskilling for employment type of programme and, instead of having my actual TEACHER do his job and explain this himself, he told us to follow this hour-long tutorial. no shade to you, mr. david, im just frustrated with the lack of preparation im getting if i am to get a job in this field.
David B. Thanks lot man, This is one of your best Videos. This is so helpful with awesome information from Rana. Iam watching this video for 3rd time now. Thank you
This is so profound, even for a learner. I've got an observation and a question, One would need the reconnaissance skill to fins out some details of the web app, like the username of the admin and other registered users, also, would like to know how to use burpe suite to create such proxy and connect the website we working on. is it okay to show few tips of those before diving into the sql injection proper? Thank you
Good to see you back Rana. Great seeing you back is awesome. you in the security field I believe is one great encouragement to ladies out there to as well join the security field. awesome. Thanks David as well.
Awsome, thanks David. Since February I have devoted myself 5 days a week for 8 hours of learning and educating myself with tryhackme, videos you have published to put me at a level where I can break into the industry, although not successful yet, it has opened my eyes to how vulnerable we really are!! Scary stuff lol😂
@david bombal really you are amazing 🎉🎉🎉🎉🎉 I Support you ,go forward , keep going you have great job 👏 to help and support the people around intee world bro 👊
one question that comes to mind , can she have a program where she talk about how to help Iranian women getting safer communicating online ? thanks for the class today! I learned a lot as a total beginner from just listening this year!
Wow, looks amazing content! Many cheers to David and Rana! And I like her voice too. Is the Udemy course a giveaway too? Because it doesn't look alike by the link provided. Happy weekend to you!
@@davidbombal Oh sorry, I was searching for my glasses everywhere, but they were tilted up on my head 😉 Anyway, all the above still applies! Thanks for these fantastic collaborations, may them be to your growth as well!
@@davidbombal Nuh, I just tried to refer that at the time of writing your comment link didn't appeared yet on my side haha, that's why I searched blindly
Don't be afraid to say we like your backing until we get up and going but we don't want you as a takeover in it we want you to help us show us the correct way to develop
Hello Mr. Bombal i wanna ask a question if you don't mind. How long you were in IT and cybersecurity and if you got something to say for a 17 years old geek can you tell.
David thank you so much for your work! I love your program. I'm about to buy the book of Occupy the Web "Getting Started Becoming a Master Hacker" but I have a doubt, 'cause I want to know if this book is updated. Could you please tell what you think? thank you again. You are amazing
professor when you interview them and i watch, it seem like the same method i use but i dont find vulns only i tried brute forcing before i gain access and use cred to connect to protocols so please let them tell the magic they use in real world because it seems like studies. please i love your channel soo much thank you professor
As most of the developers use prepared statements, do you think there is still chance of sql injection, as most of the modern frameworks have sql inject prevention built into the security components?
The recent hack of MOVEit shows that unfortunately hackers can still use SQL Injection to gain access. Watch this video for details: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-R1amgARgFDs.html
Because some people prefer Udemy, here are 1,000 free places to Rana's course (first 1,000 get the course for free): www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?couponCode=AC321B423BA301178A56
Thank you both for this great resource. I have been on this journey for a Little and every thing I can learn from this high level technical will help me to move forward. Thank you again . 🎉
Please reply here if you got the course for free! If you didn't get it in time, you can watch the course for free on RU-vid here: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-1nJgupaUPEQ.html
Dear David Bombal, only recent, OccupyTheWeb stated that the old and over-used vanilla-flavored ['admin '- -'] will NOT work, except only in a FEW cases, because over the years Database administrators have wised-up! SQL injection have become MORE sophisticated!
You need to watch the full video and course. As stated in the video, for training purposes we start with easy concepts and then increase the complexity. In the third lab in this video, Rana is doing much more complex stuff.
Sir i have problem in sqlmap i check vulnerability is available but problem is " false positive and unexploited point detected " what is the meaning of this please clear my doubts