Blind SQL Injection Made Easy

  Рет қаралды 30,219

The Cyber Mentor

The Cyber Mentor

Күн бұрын

00:00 Intro
01:12 Snyk Ad
02:31 Blind SQLi Primer
03:55 Hands-on lab
11:30 Outro
Pentests & Security Consulting: tcm-sec.com
Get Trained: academy.tcm-sec.com
Get Certified: certifications.tcm-sec.com
Merch: merch.tcm-sec.com
Sponsorship Inquiries: info@thecybermentor.com
📱Social Media📱
___________________________________________
Twitter: / thecybermentor
Twitch: / thecybermentor
Instagram: / thecybermentor
LinkedIn: / heathadams
TikTok: / thecybermentor
Discord: / discord
💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:
/ thecybermentor
Support the stream (one-time): streamlabs.com/thecybermentor
Hacker Books:
Penetration Testing: A Hands-On Introduction to Hacking: amzn.to/31GN7iX
The Hacker Playbook 3: amzn.to/34XkIY2
Hacking: The Art of Exploitation: amzn.to/2VchDyL
The Web Application Hacker's Handbook: amzn.to/30Fj21S
Real-World Bug Hunting: A Field Guide to Web Hacking: amzn.to/2V9srOe
Social Engineering: The Science of Human Hacking: amzn.to/31HAmVx
Linux Basics for Hackers: amzn.to/34WvcXP
Python Crash Course, 2nd Edition: amzn.to/30gINu0
Violent Python: amzn.to/2QoGoJn
Black Hat Python: amzn.to/2V9GpQk
My Build:
lg 32gk850g-b 32" Gaming Monitor:amzn.to/30C0qzV
darkFlash Phantom Black ATX Mid-Tower Case: amzn.to/30d1UW1
EVGA 2080TI: amzn.to/30d2lj7
MSI Z390 MotherBoard: amzn.to/30eu5TL
Intel 9700K: amzn.to/2M7hM2p
G.SKILL 32GB DDR4 RAM: amzn.to/2M638Zb
Razer Nommo Chroma Speakers: amzn.to/30bWjiK
Razer BlackWidow Chroma Keyboard: amzn.to/2V7A0or
CORSAIR Pro RBG Gaming Mouse: amzn.to/30hvg4P
Sennheiser RS 175 RF Wireless Headphones: amzn.to/31MOgpu
My Recording Equipment:
Panasonic G85 4K Camera: amzn.to/2Mk9vsf
Logitech C922x Pro Webcam: amzn.to/2LIRxAp
Aston Origin Microphone: amzn.to/2LFtNNE
Rode VideoMicro: amzn.to/309yLKH
Mackie PROFX8V2 Mixer: amzn.to/31HKOMB
Elgato Cam Link 4K: amzn.to/2QlicYx
Elgate Stream Deck: amzn.to/2OlchA5
*We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.

Пікірлер: 36
@presequel
@presequel 11 ай бұрын
nice video :) when i did this i used the numbers option as my first payload, its easier than a simplelist with typing the numbers. and i use the little searchbar at the bottom of the screen(where you typed in welcome) to typ in the chars, not shocking but a little easier than grabbing notepad to do this.
@aaftabahmed6876
@aaftabahmed6876 Жыл бұрын
Insane brother ❤
@sammy49668
@sammy49668 9 ай бұрын
great content❤
@VectorGameStudio
@VectorGameStudio Жыл бұрын
Awesome
@kumarsiddappa6118
@kumarsiddappa6118 Ай бұрын
Can we get the link for the sql cheat sheet to understand the underlying DB Vendor
@prashantrastogi1024
@prashantrastogi1024 Жыл бұрын
Stoic Alex🔥
@darrylwest3106
@darrylwest3106 4 ай бұрын
lmao🤣
@krlst.5977
@krlst.5977 Жыл бұрын
I really enjoyed your video, however i am asking you to use some other tools for such tasks. I mean Burp suite without subscription is really slow, to solve these SQL labs i used hydra for example, coz it is free and fast unlike the free version of Burp :) Anyway, thanks for such useful videos!
@presequel
@presequel 11 ай бұрын
there is a plugin, i believe it is called turbo intruder, that speeds up the proces in burp, maybe that helps ( a little). interesting idea to use hydra, i would use sqlmap or zap but never thought of doing it with hydra, will give it a try :)
@jaywandery9269
@jaywandery9269 9 ай бұрын
what query would you use to determine the table name if you did not have the information that the users table existed.
@seancantwell12
@seancantwell12 8 ай бұрын
It depends on the database software. For example, you could reference the information_schema.tables or all_tables. However, using this query in a blind SQL injection attack might be tricky but I’m sure you could figure it out.
@jaywandery9269
@jaywandery9269 8 ай бұрын
@@seancantwell12 thank you, I will definitely try this
@hkr37
@hkr37 2 ай бұрын
​@@seancantwell12 how to determine table and column names in oracle blind error based sql injection? I tried more tricks and queries. All of failed. If u know the query, pls tell me
@adityakiddo6554
@adityakiddo6554 2 ай бұрын
Before that there is one step service enumeration of sql db management systems ,, through that you can find few clues of syntaxes and use possible users table names. From web through bruteforce during live pentesting
@coders_algoritmers1032
@coders_algoritmers1032 6 ай бұрын
Sqlmap showing me false positive and unexploitable point detected even vulnerability is available what i do please tell me
@konallen1510
@konallen1510 Жыл бұрын
把数据存储在oss,只能存储不能解析?
@imnothacker_
@imnothacker_ Жыл бұрын
❤️😊
@barbarosa5063
@barbarosa5063 Жыл бұрын
Hi guys what free website do you recommend for information security courses
@killergamingfamily3039
@killergamingfamily3039 Жыл бұрын
Chek HackReveal
@darknytprivate1946
@darknytprivate1946 Жыл бұрын
hackersploit and hackerone also
@seancantwell12
@seancantwell12 8 ай бұрын
The example in the video was from Port Swigger’s free academy
@vishwagautham704
@vishwagautham704 Жыл бұрын
Do we can use windows for this activity
@adityakiddo6554
@adityakiddo6554 2 ай бұрын
No problem at all , if skilled you can solve labs like these even on a phone
@aaftabahmed6876
@aaftabahmed6876 Жыл бұрын
Can we have one video on Sqlmap 😍
@AppSecExplained
@AppSecExplained Жыл бұрын
For sure! I'll add it to the list :)
@kiiturii
@kiiturii Жыл бұрын
would be great if you showed how to do this with other tools, ain't nobody affording pro burp
@geekygymrat
@geekygymrat 6 ай бұрын
You can easily automate something like this with Python.
@kiiturii
@kiiturii 6 ай бұрын
@@geekygymrat ok bro🤦‍♀️
@darbrown19
@darbrown19 5 ай бұрын
music distracting
@ChristianRuiz-yw6ur
@ChristianRuiz-yw6ur 9 ай бұрын
that mean the password it's not encryption, right?
@seancantwell12
@seancantwell12 8 ай бұрын
Correct. In this case, the password was stored in plaintext. However, you could still use this method to find the password’s hash or encrypted value. Then once you have this value, you can attempt hash cracking or decrypting of the password.
@hkr37
@hkr37 2 ай бұрын
Pls make a tutorial video for blind sql injection with conditional error lab. They are provide table and column names, but in real time we need to find table and column names.pls make a video How to write query for find table and columns name in oracle blind error based sql injection. Tq 🎉
@hmidadeusa6286
@hmidadeusa6286 Жыл бұрын
Please, brother, teach us how to hack any Tik Tok account without software
@r.raskolnickoff1408
@r.raskolnickoff1408 Жыл бұрын
if request userID contains 'AND' send response go away n00b
@muneeburrehman547
@muneeburrehman547 8 ай бұрын
what?
How to Hack WordPress
14:06
The Cyber Mentor
Рет қаралды 69 М.
Attacking JWT - Header Injections
18:28
The Cyber Mentor
Рет қаралды 13 М.
World’s Largest Jello Pool
01:00
Mark Rober
Рет қаралды 99 МЛН
HTTP Fundamentals in 10 Minutes
10:34
The Cyber Mentor
Рет қаралды 17 М.
$100 Time Based Sql Injection Bug Bounty PoC
2:28
Marco Gonzales
Рет қаралды 7 М.
How to Hack MFA (Multi-Factor Authentication)
8:57
The Cyber Mentor
Рет қаралды 25 М.
SQLite Blind SQL Injection - HackTheBox Cyber Apocalypse CTF
35:25
John Hammond
Рет қаралды 71 М.
SQL Injection
35:40
Cyber Warriors HC
Рет қаралды 17 М.
What is the BEST Hacking Platform?
9:30
The Cyber Mentor
Рет қаралды 35 М.
SQL Injection $1000 Bounty | Bug bounty POC
3:59
The Cyberboy
Рет қаралды 32 М.
Directory Traversal attacks are scary easy
9:41
The Cyber Mentor
Рет қаралды 19 М.
Cracking JSON Web Tokens
14:34
The Cyber Mentor
Рет қаралды 56 М.
Запрещенный Гаджет для Авто с aliexpress 2
0:50
Тимур Сидельников
Рет қаралды 946 М.
Новые iPhone 16 и 16 Pro Max
0:42
Romancev768
Рет қаралды 2,3 МЛН
8 Товаров с Алиэкспресс, о которых ты мог и не знать!
49:47
РасПаковка ДваПаковка
Рет қаралды 171 М.