Union Based SQL Injection Attack For data extraction & Other Injection Flaws/Errors
Letβs talk about how you can SQL injection to retrieve interesting data. The video is detailed more on how the SQL Union attack is carried out to retrieve interesting data. I have got these three process when Iβm about to test a website: π Does the website talk to a DB? β Look for a parameter passing(e.g: site.com/page.php?id=4) β If yes - try SQL Injection π Can I or someone else see what I type? β If yes - try XSS π Does the page reference a file? β If yes - try LFI/RFI The video explains further on the points below: β Messing with the GET and POST Request β Telling FoxyProxy to use Burp Suite β Identifying SQL injection parameter passing β Understanding a Basic SQL Injection Attack β Detecting SQL Injection in an Order by Clause β SQL Injection UNION Attack β And lotβs moreβ¦β¦β¦.. Time Tags 00:00 Identifying SQL injection parameter passing 00:55 Understanding a Basic SQL Injection Attack 01:28 Detecting SQL Injection in ana Order by Clause 02:40 SQL Injection UNION Attack 04:07 Data Extraction 05:00 What you must DO as a Pentester. Web App 3 Tier Architecture 06:56 "The Error Tells the Story" Injection Flaws 08:17 XML, SPARQL, LDAD Injection 10:29 Final Thoughts π Interesting Infosecaddicts Blogpost: β Click Here: https://infosecaddicts.com/pentestbox-a-great-set-of-tools-to-start-tests/ β Click Here: https://infosecaddicts.com/free-advanced-network-pen-testing-webinar/ β Click Here for other posts: https://infosecaddicts.com/ π Join Our Free 21 Day hack-a-thon π β Register Here: https://infosecaddicts.com/free-21-day-hack-a-thon/ πSome Courses you may be interested inπ β Defensive Cyber β Malware Analysis [https://mailchi.mp/infosecaddicts/malware-analysis] β Incident Response β Reverse Engineering [https://mailchi.mp/infosecaddicts/reverse-engineering] β Offensive Cyber β Network Penetration Tester [https://mailchi.mp/infosecaddicts/network-penetration-tester] β Web App Penetration Tester [https://mailchi.mp/infosecaddicts/web-app-penetration-tester] β Red Team professional π Joe has some free challenges available if you're interested in joining in you can contact us using this link https://infosecaddicts.com/contact-us/ π You can also sign up for a customized plan https://infosecaddicts.com/customized-program/ if you need help/guidance in your career or in learning something new. π If you would like to learn more about our mentorship program you can sign up here https://mailchi.mp/infosecaddicts/mentorship π SOCIAL NETWORKS βοΈLike "InfosecAddicts" on Facebook HERE: http://bit.ly/2WQCK9a βοΈFollow InfosecAddicts on Twitter HERE: http://bit.ly/2JbIsxJ πΌ Connect with us on LinkedIn http://bit.ly/LinkedIn_InfosecAddicts ---------------------------------------------------------------------------------------- β This content is for educational purposes only. InfosecAddicts focuses on training and preparing professionals and enthusiasts, to perform Ethical Hacking, penetration testing tasks focusing on prevention and security, and developing the advancement and discussion of the Cybersecurity Field π² TRADEMARK LEGAL NOTICE: All product names, logos, videos, and brands are the property of their respective owners in the United States and/or other countries. All company, product and service names used in this video are for identification purposes only. The use of these names, logos, and brands does not imply endorsement. #SQLinjection #CodeInjection #SQLiBasics
Download
1 formatsVideo Formats
Right-click 'Download' and select 'Save Link As' if the file opens in a new tab.