No video

SQL Injection Hacking Tutorial (Beginner to Advanced)

  Рет қаралды 201,864

David Bombal

David Bombal

Күн бұрын

Пікірлер: 244
@davidbombal
@davidbombal Жыл бұрын
Learn SQL injection with Rana! Today's video demonstrates three SQL Injection attacks. Her course covers many more (9 hours of content) and you can get free access using the link below. // Labs, scripts and documents // Slides: github.com/rkhal101/Presentations/blob/main/2023/David-Bombal's-Channel/SQL%20Injection%20Video%20with%20David%20Bombal.pdf Lab #1 Link: portswigger.net/web-security/sql-injection/lab-login-bypass Lab #2 Link: portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-data-from-other-tables Lab #3 Link: portswigger.net/web-security/sql-injection/blind/lab-conditional-responses Lab #3 Python Script: github.com/rkhal101/Web-Security-Academy-Series/blob/main/sql-injection/lab-11/sqli-lab-11.py // Course options // You have multiple options: 1) KZbin: Free to watch: kzbin.info/www/bejne/Z5-tmKimlrqDe7M 2) Udemy: www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?referralCode=922314AD50A8EF6BB043 3) Rana's Academy: 50% OFF Coupon Code: "DavidBombal500FF" academy.ranakhalil.com/ Rana explains the differences in this video: kzbin.info/www/bejne/qqbbpp6Hacx-hbc // Real World Example // OTW shows SQL Injection the real world: kzbin.info/www/bejne/iGLEnpp3h8x5etU // Book Rana Recommended // Web Application’s Hacker’s handbook 2nd Ed by Dafydd Stuttard US Link: amzn.to/3J90wZa UK Link: amzn.to/3J7H2UT // Rana's SOCIAL // Twitter: twitter.com/rana__khalil Academy: academy.ranakhalil.com/ KZbin Channel: kzbin.info Medium Blog: ranakhalil101.medium.com/ Rana Intigriti Interview: kzbin.info/www/bejne/qaW7nIJ4j9iBj9E&ab_channel=intigriti // David's SOCIAL // Discord: discord.gg/davidbombal Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal // MY STUFF // www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // TIMESTAMPS // 00:00 Coming up 00:35 Disclaimer 00:40 Intro 01:00 Rana's first course 01:53 Rana's platforms 03:12 Support 04:00 SQL injection overview 05:05 SQL injection theory 09:15 Rana's background 10:19 SQL explanation 11:46 Presentation 13:10 1st lab 16:48 Discussion about practical Labs 17:57 Different types of SQL injection 21:41 2nd lab 32:14 Discussion about teaching 33:04 3rd lab 48:22 Discussion about labs 48:54 Password lockout 50:19 Cookie 51:29 3rd lab conclusion 51:49 Preventing SQL injection 57:57 Course information 58:34 SQL and developers 59:27 Course progression Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only.
@bistronauta
@bistronauta Жыл бұрын
Thanks David! The Udemy link doesn't work, regardless it's a giveaway.
@davidbombal
@davidbombal Жыл бұрын
@@bistronautaThe course is free on KZbin. But, because some people prefer Udemy, here are 1,000 free places to Rana's course (first 1,000 get the course for free): www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?couponCode=AC321B423BA301178A56
@cybersecuritycs8129
@cybersecuritycs8129 Жыл бұрын
hy david iam in pakistan and i really like your content can you please give the udemy course for free plz
@shahariarking3850
@shahariarking3850 Жыл бұрын
​@@davidbombalsir this link is not working...
@davidbombal
@davidbombal Жыл бұрын
@@shahariarking3850 Try again .... fixed...
@RanaKhalil101
@RanaKhalil101 Жыл бұрын
Thank you for having me on your channel David! I'm very excited about this collaboration 😃
@hackerzoon101
@hackerzoon101 Жыл бұрын
ZazakAllahu Kahir sister Rana Support and Prayer for you from Bangladesh 🇧🇩💐
@hackerzoon101
@hackerzoon101 Жыл бұрын
Stay blessed and keep making progress
@SweetOrchardFarms
@SweetOrchardFarms Жыл бұрын
Thank you so much, Rana! You're awesome! Keep killing it :)
@RoomTwentyNine
@RoomTwentyNine Жыл бұрын
Thank you so much Rana
@davidbombal
@davidbombal Жыл бұрын
So happy to be collaborating with you Rana! Thank you for everything you do for the community!
@hackerzoon101
@hackerzoon101 Жыл бұрын
MashAllah ما شاء الله Thank you sister Rana for the beautiful gif ZazakAllahu Kahir. Support for her from Bangladesh 🇧🇩💐
@theMadhatter817
@theMadhatter817 Жыл бұрын
This is gold! The way she explains everything is amazing. Makes it super simple and easy to follow. Definitely going to check out her full 9hr course.
@davidbombal
@davidbombal Жыл бұрын
Agreed! Rana is amazing!
@pregesor
@pregesor Жыл бұрын
You are One of the Best Teacher in KZbin 🤗
@davidbombal
@davidbombal Жыл бұрын
Thank you! Glad you think so!
@AToneForOurSins
@AToneForOurSins 20 күн бұрын
She makes it so easy to comprehend. What an incredible and well spoken instructor. 👏
@YoursTrulyRob
@YoursTrulyRob Жыл бұрын
9 hours Christmas came early. This Weeknd is going to be fun 🎉 Thank you sir for always coming through
@renn3014
@renn3014 Жыл бұрын
This is awesome !!! I also love that Rana is a woman in this space and a Hijabi woman !! 🙌 it’s great to see, this is my 1st time swing this. Great content David yet again ! Thank you! This channel has alerted me to recent cyber threat methods, taught me so much and has also pointed me in the direction of great learning resources (books, labs, videos, teachers) and it’s super useful especially considering I’m a beginner in cyber security . Thanks ☺️
@LoneWolf5960
@LoneWolf5960 Жыл бұрын
Convenient timing. I'm starting my first bug bounty with a VDP with the Dept. of State. I'm in the Recon stage but based on the progression it's possible I'd probably need a XSS or SQLi to find a bug. I already brought a short but practical course for XSS and now there's this recommended by the KZbinr who helped me get my CCNA via his Udemy Course, I know I can expect good training content. Good luck to everyone in the comments.
@davidbombal
@davidbombal Жыл бұрын
Great :) Rana's content is amazing. Port Swigger even wanted to buy her content :)
@bhavanisankar7422
@bhavanisankar7422 Жыл бұрын
Thanks david and Rana Khalil for this amazing course. Really i am very thankfull to both of you . Lots of love from india
@Mr_H.AK-47
@Mr_H.AK-47 Жыл бұрын
I LOVE YOU DAVIDDD. you always post great videos and explain it in such a way that's mesmerizing. I turned 17 this 13th of july and i have been watching your videos from the age of 13 . i really appreciate your content. you have given me soo much motivation and inspiration and have inspired me to choose cyber security as a career later in life. LOVE FROM PAKISTAN SIRR🥰🥰
@user-xh3ut2sm9g
@user-xh3ut2sm9g Ай бұрын
Hey, there , just wanna say thanks for such great content and a wide variety of topics, really helpful Love from South Africa 🇿🇦
@sidalexis
@sidalexis Жыл бұрын
Took this course on Udemy yesterday Just one piece of feedback: The font on VS code needs to be a bit larger 😊
@SweetOrchardFarms
@SweetOrchardFarms Жыл бұрын
Thank you so much, guys! I love your channel, David!
@ramseshernandez3725
@ramseshernandez3725 Жыл бұрын
Waooooo, was great to watch this video, thanks for share other level to learn sql injection; Thanks David and Rana 👍,
@superdupercorp
@superdupercorp 11 ай бұрын
im on a reskilling for employment type of programme and, instead of having my actual TEACHER do his job and explain this himself, he told us to follow this hour-long tutorial. no shade to you, mr. david, im just frustrated with the lack of preparation im getting if i am to get a job in this field.
@miss_nainuu
@miss_nainuu Жыл бұрын
She's really great and talented expert. Very helpful video😊
@ryanten6475
@ryanten6475 Жыл бұрын
absolutely love her ❤❤❤❤
@scott8964
@scott8964 Жыл бұрын
God bless you both love to see more people helping others
@geniustic1541
@geniustic1541 Жыл бұрын
Thank you for making the course available on KZbin, both you guys! God bless
@txfalkon2882
@txfalkon2882 Жыл бұрын
Good to see you back Rana. Great seeing you back is awesome. you in the security field I believe is one great encouragement to ladies out there to as well join the security field. awesome. Thanks David as well.
@AadiLAit
@AadiLAit 11 ай бұрын
David B. Thanks lot man, This is one of your best Videos. This is so helpful with awesome information from Rana. Iam watching this video for 3rd time now. Thank you
@toluwajoe5680
@toluwajoe5680 7 ай бұрын
This is so profound, even for a learner. I've got an observation and a question, One would need the reconnaissance skill to fins out some details of the web app, like the username of the admin and other registered users, also, would like to know how to use burpe suite to create such proxy and connect the website we working on. is it okay to show few tips of those before diving into the sql injection proper? Thank you
@vikk98
@vikk98 Жыл бұрын
love from village (India) i most watch your video alway awesome
@Patriotic8422
@Patriotic8422 Жыл бұрын
*Very informative and useful fr me* 🙏
@demotedc0der
@demotedc0der Жыл бұрын
everything explained very clear,,, such a great content david ''' we need more like this
@general.commander.1
@general.commander.1 Жыл бұрын
شكرا الاستاذ ديفيد على المعلومات التى تنشرها لنا لك التحية من مصر
@joshuadughi
@joshuadughi Жыл бұрын
Great content, Again!! Thank you, David! Thank you, Rana!
@naadiaheimers1705
@naadiaheimers1705 Жыл бұрын
its been 11 years since someone teached me sql injection, and i never get bored
@olumideajose2162
@olumideajose2162 Жыл бұрын
just snagged it on udemy, You guyz are amazing. Stay Blessed
@AbdAlkarimTube
@AbdAlkarimTube Жыл бұрын
Great video, We need more from Rana! Thanks.
@meta-zeno505
@meta-zeno505 Жыл бұрын
I missed my last chance, not missing this one!!!!! Plus I love SQL work!!!!
@davidbombal
@davidbombal Жыл бұрын
The course is free on KZbin, so no rush :)
@meta-zeno505
@meta-zeno505 Жыл бұрын
Awsome, thanks David. Since February I have devoted myself 5 days a week for 8 hours of learning and educating myself with tryhackme, videos you have published to put me at a level where I can break into the industry, although not successful yet, it has opened my eyes to how vulnerable we really are!! Scary stuff lol😂
@jb-spaceworld2069
@jb-spaceworld2069 Жыл бұрын
Absolutely brilliant stuff David! Where did you find this amazing legend? Rana, thank you so much.....am totally in!
@the_yugandharr
@the_yugandharr 4 ай бұрын
very well explained by Rana
@davidbombal
@davidbombal Жыл бұрын
Because some people prefer Udemy, here are 1,000 free places to Rana's course (first 1,000 get the course for free): www.udemy.com/course/mastering-sql-injection-the-ultimate-hands-on-course/?couponCode=AC321B423BA301178A56
@mistacoolie8481
@mistacoolie8481 Жыл бұрын
Thank you both for this great resource. I have been on this journey for a Little and every thing I can learn from this high level technical will help me to move forward. Thank you again . 🎉
@davidbombal
@davidbombal Жыл бұрын
Please reply here if you got the course for free! If you didn't get it in time, you can watch the course for free on KZbin here: kzbin.info/www/bejne/Z5-tmKimlrqDe7M
@Ganesh-lq7op
@Ganesh-lq7op Жыл бұрын
Thank you sir ❤
@shahariarking3850
@shahariarking3850 Жыл бұрын
​@@davidbombalthank you sir and Rana this link working properly....
@ronaldmacheka2180
@ronaldmacheka2180 Жыл бұрын
@@davidbombal got the course thank you
@mfahad710
@mfahad710 11 ай бұрын
Amazing Stuff Rana Khalil
@SimplicityForGood
@SimplicityForGood Жыл бұрын
one question that comes to mind , can she have a program where she talk about how to help Iranian women getting safer communicating online ? thanks for the class today! I learned a lot as a total beginner from just listening this year!
@gulshanyadav3140
@gulshanyadav3140 Жыл бұрын
Thank you very much David and Rana!!
@adewolekayode6148
@adewolekayode6148 Жыл бұрын
This is very interesting. God bless you more ..❤
@z0nerider
@z0nerider Жыл бұрын
Awesome work @rana and great content @david as usual !! Loved the mathematics joke btw 😀
@Engsfscrypto
@Engsfscrypto 9 ай бұрын
@david bombal really you are amazing 🎉🎉🎉🎉🎉 I Support you ,go forward , keep going you have great job 👏 to help and support the people around intee world bro 👊
@hackerzoon101
@hackerzoon101 Жыл бұрын
David your doing great, bring intalactuls along side with recourses and lab I appreciate for your kind affort brother
@bistronauta
@bistronauta Жыл бұрын
Wow, looks amazing content! Many cheers to David and Rana! And I like her voice too. Is the Udemy course a giveaway too? Because it doesn't look alike by the link provided. Happy weekend to you!
@davidbombal
@davidbombal Жыл бұрын
Hint... Look for for my comment :)
@bistronauta
@bistronauta Жыл бұрын
@@davidbombal Oh sorry, I was searching for my glasses everywhere, but they were tilted up on my head 😉 Anyway, all the above still applies! Thanks for these fantastic collaborations, may them be to your growth as well!
@davidbombal
@davidbombal Жыл бұрын
@@bistronauta You have time to get it... refresh the page and look for my comment :)
@bistronauta
@bistronauta Жыл бұрын
@@davidbombal Nuh, I just tried to refer that at the time of writing your comment link didn't appeared yet on my side haha, that's why I searched blindly
@xRiPw0lFx
@xRiPw0lFx Жыл бұрын
Love seeing intelligent women well-versed in cybersecurity 😉😉😁😁
@royalonlineboy
@royalonlineboy Жыл бұрын
I love the way she explains things.
@PandaBero83
@PandaBero83 Жыл бұрын
Realy good content! the onlyy thing is the background of Ranal video... if i look at the coding, she get blured and all i see is a funny flying head..
@ariasm8911
@ariasm8911 Жыл бұрын
this give me goosebump, great content
@bekame4548
@bekame4548 Жыл бұрын
Thank you David ,good job Rana 👍
@mariusgjura-beluga
@mariusgjura-beluga 11 ай бұрын
Thank you so much . I have already shut down and deleted over 20 government websites on my country
@user-el8yx7eh3h
@user-el8yx7eh3h 9 ай бұрын
I was like....whaaaat, this woman looks like an innocent housewife, would never expect this from her...hahaha nicely done
@mohamedamrani4853
@mohamedamrani4853 Жыл бұрын
God bless you sister rana
@xwinglover
@xwinglover Жыл бұрын
What a great presentation
@AWhite_
@AWhite_ Жыл бұрын
Great Course, thank you so much.
@colton923
@colton923 Жыл бұрын
What a perfect new subject to learn.
@ElevenOO1
@ElevenOO1 Жыл бұрын
Great collection
@arashautomationlab9088
@arashautomationlab9088 Жыл бұрын
Thank you sister الحمدالله
@DevakiNandhan
@DevakiNandhan Жыл бұрын
Ya..???? This is best course in KZbin @Rana
@muhon19
@muhon19 Жыл бұрын
Masha allha good see you sisters
@DaniMHMDI
@DaniMHMDI Жыл бұрын
Great as always 👑
@davidbombal
@davidbombal Жыл бұрын
Thank you!
@McduduTQ
@McduduTQ Жыл бұрын
8 +HOURS OF LAB....SWEET
@cuti9114
@cuti9114 Жыл бұрын
Thankyou so much great tutorial leart alot😊❤
@SabonaMarara
@SabonaMarara 7 ай бұрын
wow great video!
@alisenjary
@alisenjary Жыл бұрын
Thanks David and rana ❤❤
@mmuhamme2001
@mmuhamme2001 Жыл бұрын
Love your content ❤
@hardeepsingh_07
@hardeepsingh_07 Жыл бұрын
Thank again I wating for this ❤
@davidbombal
@davidbombal Жыл бұрын
I hope you enjoy the content!
@hardeepsingh_07
@hardeepsingh_07 Жыл бұрын
Yes sir thank you ❤️❤️
@micah6465
@micah6465 Жыл бұрын
Danggg what an excellent teacher 😅
@user-yw4lf8um7m
@user-yw4lf8um7m Жыл бұрын
David thank you so much for your work! I love your program. I'm about to buy the book of Occupy the Web "Getting Started Becoming a Master Hacker" but I have a doubt, 'cause I want to know if this book is updated. Could you please tell what you think? thank you again. You are amazing
@TheErixcode
@TheErixcode 10 ай бұрын
47:50 this is how Hollywood password cracking presented xD
@CYBER-HERO
@CYBER-HERO Жыл бұрын
Hello Mr. Bombal i wanna ask a question if you don't mind. How long you were in IT and cybersecurity and if you got something to say for a 17 years old geek can you tell.
@AhmedAli5530
@AhmedAli5530 Жыл бұрын
As most of the developers use prepared statements, do you think there is still chance of sql injection, as most of the modern frameworks have sql inject prevention built into the security components?
@davidbombal
@davidbombal Жыл бұрын
The recent hack of MOVEit shows that unfortunately hackers can still use SQL Injection to gain access. Watch this video for details: kzbin.info/www/bejne/iGLEnpp3h8x5etU
@kimutaifelix9092
@kimutaifelix9092 Жыл бұрын
She's Good 👏👏👏💪
@RIPscammers
@RIPscammers Жыл бұрын
Hey david, do you know what is happening in India in the Manipur case
@ekwuruibemarshalnnamdi9239
@ekwuruibemarshalnnamdi9239 Жыл бұрын
Thank you David
@davidbombal
@davidbombal Жыл бұрын
You're welcome!
@kentapostol6909
@kentapostol6909 Жыл бұрын
Great ❤
@PhilosophyEpochs
@PhilosophyEpochs Жыл бұрын
thank you david SIR !
@davidbombal
@davidbombal Жыл бұрын
You're welcome! Rana is amazing and we can learn so much from her!
@nunoalexandre6408
@nunoalexandre6408 Жыл бұрын
Love it!!!!!!!!!!!!!!!!!!!!!
@Rbx_Corrupted
@Rbx_Corrupted Жыл бұрын
thank you very much ❤❤❤
@marciodias778
@marciodias778 Жыл бұрын
Excelente video, mas poderia ter tradução para português Brasil, por favor!
@affulsamuel728
@affulsamuel728 Жыл бұрын
professor when you interview them and i watch, it seem like the same method i use but i dont find vulns only i tried brute forcing before i gain access and use cred to connect to protocols so please let them tell the magic they use in real world because it seems like studies. please i love your channel soo much thank you professor
@vilma-lima5295
@vilma-lima5295 Жыл бұрын
top,,, i like very good
@ahmadmikati3397
@ahmadmikati3397 Жыл бұрын
@ranakhalil101, we are super proud of you! Well done!
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
Fantastic!
@davidbombal
@davidbombal Жыл бұрын
Glad you like it! Enjoy the course!
@camelotenglishtuition6394
@camelotenglishtuition6394 Жыл бұрын
@davidbombal thank you .. I'm just working through blackhat api but will jump on this at some point
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz Жыл бұрын
Needed this!
@davidbombal
@davidbombal Жыл бұрын
Hope the course helps you! Rana has lots of fantastic content on her channel - even more than this!
@w3sp
@w3sp Жыл бұрын
Great video. Dumb question: Does that '-- exploit only work if there are no line breaks in an SQL?
@my-rules
@my-rules Жыл бұрын
Thanks a lot
@borhen-di6ik
@borhen-di6ik Жыл бұрын
Hello David, can You make a video about Cyber Security, Thanks
@AadiLAit
@AadiLAit 11 ай бұрын
Perfect Demos for new learners :-)
@TonyFarley-gi2cv
@TonyFarley-gi2cv Жыл бұрын
Don't be afraid to say we like your backing until we get up and going but we don't want you as a takeover in it we want you to help us show us the correct way to develop
@KProjects-qo5ix
@KProjects-qo5ix Жыл бұрын
Love it 😌...kinda new to this tho
@affulsamuel728
@affulsamuel728 Жыл бұрын
i love your videos
@yvng4697
@yvng4697 Жыл бұрын
Mashallah
@user-gp7zm7gs9n
@user-gp7zm7gs9n 8 ай бұрын
How does this password bruteforce initially work? It guesses each character based on what?
@FruchtDesZorns
@FruchtDesZorns Жыл бұрын
Wow, I'm your next student
@ggx96
@ggx96 Жыл бұрын
Rana looks like Trenton from mr.robot, she can probably get our credential in a few minute, better do not mess with her 😆
@73dines
@73dines Жыл бұрын
Rana is the real life Trenton from Mr Robot. ☺
@mynameiskranz
@mynameiskranz Жыл бұрын
method POST is more saver, right?
@sebitguado2058
@sebitguado2058 Жыл бұрын
Thank you boss❤❤❤
@davidbombal
@davidbombal Жыл бұрын
Thank you! I'm just trying to help as many people as I can :)
@apristen
@apristen 9 ай бұрын
SQL prepared statements and WAFs are eliminated all SQL injections threats in 2023 😋
@barkhadibraahim1023
@barkhadibraahim1023 Жыл бұрын
great video
@davidbombal
@davidbombal Жыл бұрын
Thank you! Rana is amazing!
@raposo6359
@raposo6359 Жыл бұрын
Poucos irão ver até o final! Few will see until the end!
Hacker hunting with Wireshark (even if SSL encrypted!)
1:07:16
David Bombal
Рет қаралды 262 М.
SQL Injection Beginner Crash Course
30:00
zSecurity
Рет қаралды 59 М.
а ты любишь париться?
00:41
KATYA KLON LIFE
Рет қаралды 3,5 МЛН
SPONGEBOB POWER-UPS IN BRAWL STARS!!!
08:35
Brawl Stars
Рет қаралды 17 МЛН
ISSEI & yellow girl 💛
00:33
ISSEI / いっせい
Рет қаралды 24 МЛН
Linux for Hackers Tutorial (And Free Courses)
1:11:50
David Bombal
Рет қаралды 765 М.
Buffer Overflow Hacking Tutorial (Bypass Passwords)
55:39
David Bombal
Рет қаралды 73 М.
SQL Injection | Complete Guide
1:11:53
Rana Khalil
Рет қаралды 240 М.
SQL Injection Attack Tutorial - I didn't know you can do that
12:59
Loi Liang Yang
Рет қаралды 33 М.
Real World Hacking Demo with OTW
40:51
David Bombal
Рет қаралды 226 М.
Using My Python Skills To Punish Credit Card Scammers
7:13
Engineer Man
Рет қаралды 4,9 МЛН
Do you have what it takes to get into Cybersecurity in 2024
8:57
Tech with Jono
Рет қаралды 496 М.
а ты любишь париться?
00:41
KATYA KLON LIFE
Рет қаралды 3,5 МЛН