CTF Guide / Python Prjoect - Automating SQL Injection

  Рет қаралды 564

Gand0rf

Gand0rf

Күн бұрын

Пікірлер: 7
@kaueberto8384
@kaueberto8384 6 күн бұрын
So instructive. Thanks for your channel!
@heathbruce9928
@heathbruce9928 Ай бұрын
Does this attack work with Microsoft sites? The normal Ms query has brackets which would cause the query to fail.
@gand0rfTRZ
@gand0rfTRZ Ай бұрын
It all depends on the database used on the backend. Thats why it is normally a good habit to have several txt files with different payloads. Scripts like this can also be tweeked for different cases. Or you can make several scripts. One for sql, nosql, or what ever you come across. The key is learning the differences and building a tools that can work with the different types.
@Evan-bjc4w
@Evan-bjc4w Ай бұрын
Any ways to protect my site from this?
@gand0rfTRZ
@gand0rfTRZ Ай бұрын
Input validation and an IDS like Suricata would go a long way to help.
@Evan-bjc4w
@Evan-bjc4w Ай бұрын
@@gand0rfTRZ what is ids?
@gand0rfTRZ
@gand0rfTRZ Ай бұрын
Intrusuon Detection System. I use suricata on my web site. I had a big problem with spray and pray ssh login attempts. After setting it up and adding a rule to drop ssh connects, and adding a ufw rule to only allow ssh logins from the ip address of a mchine I control. The ssh brute forcing has been stopped and isnt taking up resources on my server or clogging up my SIEM logs.
CTF Guide - Putting recon step together
11:57
Gand0rf
Рет қаралды 173
SQLc is the perfect tool for those who don't like ORMs
28:11
Dreams of Code
Рет қаралды 105 М.
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 200 МЛН
Players vs Pitch 🤯
00:26
LE FOOT EN VIDÉO
Рет қаралды 128 МЛН
THM BreakMe Walkthrough
23:49
Gand0rf
Рет қаралды 734
SQLite Blind SQL Injection - HackTheBox Cyber Apocalypse CTF
35:25
John Hammond
Рет қаралды 72 М.
CTF Guide - Nmap
15:57
Gand0rf
Рет қаралды 307
Teaching Neovim From Scratch To A Noob
1:12:55
TheVimeagen
Рет қаралды 228 М.
SQL Injection Attack Tutorial - I didn't know you can do that
12:59
Loi Liang Yang
Рет қаралды 39 М.
DRM explained - How Netflix prevents you from downloading videos?
18:17
Mehul - Codedamn
Рет қаралды 220 М.
Automate your job with Python
6:07
John Watson Rooney
Рет қаралды 426 М.
Не бойтесь экраны "водопады"
1:00
Бананикс
Рет қаралды 382 М.
Me Charging My Phone Before Going Out
0:18
Godfrey Twins
Рет қаралды 11 МЛН
HONOR MAGIC 7 PRO. ПЕРВЫЙ ОБЗОР В РОССИИ
20:21
ЧЕСТНЫЙ БЛОГ
Рет қаралды 58 М.