Blind SQL Injection Made Easy

  Рет қаралды 28,309

The Cyber Mentor

The Cyber Mentor

Күн бұрын

00:00 Intro
01:12 Snyk Ad
02:31 Blind SQLi Primer
03:55 Hands-on lab
11:30 Outro
Pentests & Security Consulting: tcm-sec.com
Get Trained: academy.tcm-sec.com
Get Certified: certifications.tcm-sec.com
Merch: merch.tcm-sec.com
Sponsorship Inquiries: info@thecybermentor.com
📱Social Media📱
___________________________________________
Twitter: / thecybermentor
Twitch: / thecybermentor
Instagram: / thecybermentor
LinkedIn: / heathadams
TikTok: / thecybermentor
Discord: / discord
💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:
/ thecybermentor
Support the stream (one-time): streamlabs.com/thecybermentor
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
The Hacker Playbook 3: amzn.to/34XkIY2
Hacking: The Art of Exploitation: amzn.to/2VchDyL
The Web Application Hacker's Handbook: amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
Social Engineering: The Science of Human Hacking: amzn.to/31HAmVx
Linux Basics for Hackers: amzn.to/34WvcXP
Python Crash Course, 2nd Edition: amzn.to/30gINu0
Violent Python: amzn.to/2QoGoJn
Black Hat Python: amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
EVGA 2080TI: amzn.to/30d2lj7
MSI Z390 MotherBoard: amzn.to/30eu5TL
Intel 9700K: amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
Razer Nommo Chroma Speakers: amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
My Recording Equipment:
Panasonic G85 4K Camera: amzn.to/2Mk9vsf
Logitech C922x Pro Webcam: amzn.to/2LIRxAp
Aston Origin Microphone: amzn.to/2LFtNNE
Rode VideoMicro: amzn.to/309yLKH
Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
Elgato Cam Link 4K: amzn.to/2QlicYx
Elgate Stream Deck: amzn.to/2OlchA5
*We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.

Пікірлер: 36
@aaftabahmed6876
@aaftabahmed6876 Жыл бұрын
Insane brother ❤
@presequel
@presequel 10 ай бұрын
nice video :) when i did this i used the numbers option as my first payload, its easier than a simplelist with typing the numbers. and i use the little searchbar at the bottom of the screen(where you typed in welcome) to typ in the chars, not shocking but a little easier than grabbing notepad to do this.
@sammy49668
@sammy49668 7 ай бұрын
great content❤
@prashantrastogi1024
@prashantrastogi1024 Жыл бұрын
Stoic Alex🔥
@darrylwest3106
@darrylwest3106 3 ай бұрын
lmao🤣
@VectorGameStudio
@VectorGameStudio Жыл бұрын
Awesome
@krlst.5977
@krlst.5977 Жыл бұрын
I really enjoyed your video, however i am asking you to use some other tools for such tasks. I mean Burp suite without subscription is really slow, to solve these SQL labs i used hydra for example, coz it is free and fast unlike the free version of Burp :) Anyway, thanks for such useful videos!
@presequel
@presequel 10 ай бұрын
there is a plugin, i believe it is called turbo intruder, that speeds up the proces in burp, maybe that helps ( a little). interesting idea to use hydra, i would use sqlmap or zap but never thought of doing it with hydra, will give it a try :)
@jaywandery9269
@jaywandery9269 7 ай бұрын
what query would you use to determine the table name if you did not have the information that the users table existed.
@seancantwell12
@seancantwell12 6 ай бұрын
It depends on the database software. For example, you could reference the information_schema.tables or all_tables. However, using this query in a blind SQL injection attack might be tricky but I’m sure you could figure it out.
@jaywandery9269
@jaywandery9269 6 ай бұрын
@@seancantwell12 thank you, I will definitely try this
@hkr37
@hkr37 Ай бұрын
​@@seancantwell12 how to determine table and column names in oracle blind error based sql injection? I tried more tricks and queries. All of failed. If u know the query, pls tell me
@adityakiddo6554
@adityakiddo6554 23 күн бұрын
Before that there is one step service enumeration of sql db management systems ,, through that you can find few clues of syntaxes and use possible users table names. From web through bruteforce during live pentesting
@kumarsiddappa6118
@kumarsiddappa6118 17 сағат бұрын
Can we get the link for the sql cheat sheet to understand the underlying DB Vendor
@imnothacker_
@imnothacker_ Жыл бұрын
❤️😊
@barbarosa5063
@barbarosa5063 Жыл бұрын
Hi guys what free website do you recommend for information security courses
@killergamingfamily3039
@killergamingfamily3039 Жыл бұрын
Chek HackReveal
@darknytprivate1946
@darknytprivate1946 Жыл бұрын
hackersploit and hackerone also
@seancantwell12
@seancantwell12 6 ай бұрын
The example in the video was from Port Swigger’s free academy
@aaftabahmed6876
@aaftabahmed6876 Жыл бұрын
Can we have one video on Sqlmap 😍
@AppSecExplained
@AppSecExplained Жыл бұрын
For sure! I'll add it to the list :)
@konallen1510
@konallen1510 Жыл бұрын
把数据存储在oss,只能存储不能解析?
@kiiturii
@kiiturii 11 ай бұрын
would be great if you showed how to do this with other tools, ain't nobody affording pro burp
@geekygymrat
@geekygymrat 5 ай бұрын
You can easily automate something like this with Python.
@kiiturii
@kiiturii 5 ай бұрын
@@geekygymrat ok bro🤦‍♀️
@coders_algoritmers1032
@coders_algoritmers1032 4 ай бұрын
Sqlmap showing me false positive and unexploitable point detected even vulnerability is available what i do please tell me
@vishwagautham704
@vishwagautham704 Жыл бұрын
Do we can use windows for this activity
@adityakiddo6554
@adityakiddo6554 23 күн бұрын
No problem at all , if skilled you can solve labs like these even on a phone
@ChristianRuiz-yw6ur
@ChristianRuiz-yw6ur 8 ай бұрын
that mean the password it's not encryption, right?
@seancantwell12
@seancantwell12 6 ай бұрын
Correct. In this case, the password was stored in plaintext. However, you could still use this method to find the password’s hash or encrypted value. Then once you have this value, you can attempt hash cracking or decrypting of the password.
@darbrown19
@darbrown19 4 ай бұрын
music distracting
@hkr37
@hkr37 Ай бұрын
Pls make a tutorial video for blind sql injection with conditional error lab. They are provide table and column names, but in real time we need to find table and column names.pls make a video How to write query for find table and columns name in oracle blind error based sql injection. Tq 🎉
@hmidadeusa6286
@hmidadeusa6286 Жыл бұрын
Please, brother, teach us how to hack any Tik Tok account without software
@r.raskolnickoff1408
@r.raskolnickoff1408 Жыл бұрын
if request userID contains 'AND' send response go away n00b
@muneeburrehman547
@muneeburrehman547 7 ай бұрын
what?
How to Hack WordPress
14:06
The Cyber Mentor
Рет қаралды 64 М.
What is the BEST Hacking Platform?
9:30
The Cyber Mentor
Рет қаралды 34 М.
Climbing to 18M Subscribers 🎉
00:32
Matt Larose
Рет қаралды 31 МЛН
🍕Пиццерия FNAF в реальной жизни #shorts
00:41
SQL Injection Beginner Crash Course
30:00
zSecurity
Рет қаралды 55 М.
SQLite Blind SQL Injection - HackTheBox Cyber Apocalypse CTF
35:25
John Hammond
Рет қаралды 70 М.
Avoid "OR 1=1" in SQL Injections
10:56
The Cyber Mentor
Рет қаралды 24 М.
12- Detecting SQL Injection Vulnerability using OWASP ZAP
26:34
Test Automation with Atul Sharma
Рет қаралды 4,3 М.
SQL Injection Attack Tutorial - I didn't know you can do that
12:59
Loi Liang Yang
Рет қаралды 28 М.
SQL Injection | Complete Guide
1:11:53
Rana Khalil
Рет қаралды 228 М.
Time-Based Blind SQL Injection!
12:17
Intigriti
Рет қаралды 20 М.
SQL Injecting Beyond Strict Filters - Union Without Comma
36:21
How to Prevent, Detect, and Respond to Attacks with this Free Tool?
29:39
advanced SQL injection
12:18
Loi Liang Yang
Рет қаралды 56 М.
МОЩНЕЕ ТВОЕГО ПК - iPad Pro M4 (feat. Brickspacer)
28:01
ЗЕ МАККЕРС
Рет қаралды 86 М.
How charged your battery?
0:14
V.A. show / Магика
Рет қаралды 6 МЛН
ТОП-5 культовых телефонов‼️
1:00
Pedant.ru
Рет қаралды 19 М.
Разряженный iPhone может больше Android
0:34