SQL Injection | Complete Guide

Поделиться
HTML-код
  • Опубликовано: 24 ноя 2024

Комментарии • 327

  • @RanaKhalil101
    @RanaKhalil101  3 года назад +74

    Interested in supporting me and gaining early access to the Web Security Academy videos when they're recorded? Consider buying my course: academy.ranakhalil.com/p/web-security-academy-video-series! ✨ ✨

    • @bigbrain786
      @bigbrain786 3 года назад +2

      i don't have money to purchase .

    • @omarc900
      @omarc900 3 года назад +6

      @@bigbrain786 $29 save up.

    • @i_youtube_
      @i_youtube_ 2 года назад

      Is buying the course is intended to support you or there is an additional content added in the paid course.

    • @SauravKumar-if4to
      @SauravKumar-if4to Год назад

      I don't have money 🥺🥺 so i come here to see

  • @eonraider
    @eonraider 3 года назад +176

    Your video material is actually way better than the instructions provided in the academy itself. The guys at the academy would be crazy not to approach you to incorporate your material into their platform.

    • @RanaKhalil101
      @RanaKhalil101  3 года назад +65

      your comment made my day!

    • @eonraider
      @eonraider 3 года назад +15

      @@RanaKhalil101 That's great! I'm glad I found your write-ups too. It's just sheer competence right there. Keep up the good work.

    • @gg-ps1vz
      @gg-ps1vz 3 года назад +1

      @@eonraider GG twitter.com/PortSwigger/status/1366714766895550469?s=19

    • @comosaycomosah
      @comosaycomosah Год назад

      This

  • @logosmaxima2775
    @logosmaxima2775 3 года назад +15

    Where have you been all my life? Please continue working on this. This is great!

    • @hilalkhan8446
      @hilalkhan8446 5 месяцев назад +2

      Yes........ and You comment ( My heart's words).

  • @hacktrader29
    @hacktrader29 3 года назад +4

    I am totally new to this world , but your video is good to understand. Thanks

  • @bakeery
    @bakeery Год назад +1

    Subhallah! This is what I spend so many months looking for, finally gotten it for free, Thanks alot for the resources.

  • @Lwyte17
    @Lwyte17 Год назад +2

    Your material answers all the questions I have when doing the lab's when I think of "what if..." and it really helps complete the whole picture. Will probably sign up soon when I have some time and money!

  • @mian_al_ruhanyat
    @mian_al_ruhanyat 11 месяцев назад +1

    I always hate theory but your theory videos are so practical that you can't imagine. It's helping me a lot.

  • @faux3250
    @faux3250 7 месяцев назад

    This was extremely helpful! As someone who was a bit lost in the Web Security Academy this helped fill in the gaps so much. Thank you for this!

  • @shankaranand7761
    @shankaranand7761 3 года назад +3

    Very comprehensive and insightful. Never had anyone explain SQL injection in such a manner. Was very easy to follow through. Thank you. Great work! Awaiting more content.👍

  • @sporkaccione
    @sporkaccione 3 года назад +9

    Amazing work, I'm looking forward to the rest of this series!!

  • @jotunheim1491
    @jotunheim1491 3 года назад +3

    Thank you so much, amazing work. Actually it's the most up-to-date work, covering everything from a white/grey/black box perspective. Again, thank you! You are awesome :D

  • @panduancloud4699
    @panduancloud4699 3 года назад

    This is first youtube video without dislike i have ever seen. NICE and thank you for the tutorials.

  • @irfanullah9375
    @irfanullah9375 2 года назад

    I am here after watching the Broken access vulnerability topic with David Bombal. The way of your teaching is outstanding and thanks for sharing such a valuable knowledge.

  • @farisalshareef107
    @farisalshareef107 3 года назад

    You know I have never wrote a single comment in RUclips but your videos make me do it . Thank you so much for your video and please keep it up 👏

  • @stabgan
    @stabgan 3 года назад +2

    Your voice is so soothing. Loved your content. Subscribed

  • @greyhat430
    @greyhat430 11 месяцев назад +1

    thank you soo much ma'am !!

  • @choyanhalder1211
    @choyanhalder1211 3 года назад +1

    This video is so important for beginner.Thanks a lot mam for your great initiative.please keep it continuous.

  • @esadecimale
    @esadecimale 3 года назад +1

    Reviewing some of these things to fresh up my memory in order to create my own content on the subject (but in italian), and well, excellently explained, thank you very much!

  • @boneitch
    @boneitch 2 года назад +1

    These videos are so awesome that I'm watching and taking notes on New Year's Eve, and I'm truly enjoying myself. Thank you! (And happy new year!)

    • @RanaKhalil101
      @RanaKhalil101  2 года назад +1

      This comment made my day! Happy new year!

  • @fahadbawazir1771
    @fahadbawazir1771 3 года назад +1

    MASHALLAH, PROFESSIONAL WAY OF PRESENTATION

  • @vishalcv3263
    @vishalcv3263 2 года назад +1

    Your teaching methodolgy is really amazing. I have no previous tech experience a complete newbie with some basic knowledge and I completey understand what is being explained. Thank you so much for putting in so much of time and efforts and keep up the good work ma'm.

  • @amazingfacts8910
    @amazingfacts8910 4 дня назад +1

    Clear my all doubts,Thnx😊

  • @nOneimportant11192a
    @nOneimportant11192a Год назад +1

    You are AMAZING! Thank you so much for all the effort and time to bring such an excellent content to the community. You are an inspiration!

  • @neerajkharwar6141
    @neerajkharwar6141 3 года назад +1

    thanks for uploading this video I was constantly looking for the resource to study this topic and I finally found this video... it is very helpful

  • @ehabahmedyassen
    @ehabahmedyassen Год назад +3

    Thank you so much for your amazing course, your effort and your time! I really like the consistency in the slides format & flow of explanation for each topic and how you organise the playlists for each topic with short and long versions 😊

  • @prabakarj4797
    @prabakarj4797 3 года назад

    Wow!! Simply awesome! Finally I found a channel which Deep dive into the SQL injection!

  • @MrNightowl1980
    @MrNightowl1980 3 года назад +1

    I think that you and the company you work for are amazing! Thank you for these vids!🙂

  • @zahidazafar7696
    @zahidazafar7696 3 года назад +4

    incredibly impressed this is fantastic

  • @hacklikeAgbaby
    @hacklikeAgbaby 6 месяцев назад

    with this guide, its easy to understand SQLI , thank u

  • @barebears289
    @barebears289 3 года назад +1

    You're the best! I love your work, and I have learned a lot from you! You deserve a million subs. Tysm😄

  • @mohammadmaniruddin7921
    @mohammadmaniruddin7921 3 года назад +1

    Completed the whole video. Going for the next one. Thank you so much for sharing the awesome knowledge ❤️

  • @aaronwhite1786
    @aaronwhite1786 3 года назад +2

    I've been studying for the GSEC for work, and it's really taken away time from all of my offensive security studying, but I'm finally sitting down for some free time to study and checking out your tutorials. They've all looked great from the handful I've watched while on in the background while working, but I'm looking forward to really digging in and using them to get ready for the Burpsuite Cert after my GSEC test in December.
    Thanks for all of the hard work!

    • @aaronwhite1786
      @aaronwhite1786 9 месяцев назад

      Ha! Saw my old comment here and figured I'd update. I got the GSEC checked out, and now I'm back learning all of this all over again since I'm studying for the GWAPT.
      Thanks again for all of the great videos!

  • @a.sstudio6321
    @a.sstudio6321 3 года назад

    Love from Pakistan....simple and easy way of teaching...

  • @davidobber6788
    @davidobber6788 2 года назад

    WOW! Excellent video that clearly explains how we have to think twice (or more) before feeling safe!

  • @rodrigoa.cascao1553
    @rodrigoa.cascao1553 Год назад +1

    I found out about your work on David Bombal's channel. Your channel is fantastic!

  • @absoluteepic1703
    @absoluteepic1703 3 года назад +1

    Best explanation I would say, simple and straight! Very helpful, thank you!

  • @mohammedal-shaboti7939
    @mohammedal-shaboti7939 3 года назад +1

    Your methodology of testing is great. Well done!

  • @gluonboson
    @gluonboson Год назад

    This presentation is realy realy useful for beginners or students , it explains every details of the topic and and has example of queries and payloads for real-life stuations . Please keep going to do it for young collegues and students. Thank you for your effort.

  • @davneg01
    @davneg01 Год назад

    Thanks so much, very clear, appreciate all of your hard work behind the scenes

  • @ragnarlothbrok367
    @ragnarlothbrok367 3 года назад +1

    You are doing great job teaching! I wish I could have your determination and attention to detail!

  • @MrHbk7172
    @MrHbk7172 2 года назад

    Finest Video On SQL Injection on RUclips ❤

  • @kydo2540
    @kydo2540 3 года назад +1

    Huge fan! Been following you since the days of your medium writeups. Thank you for your content, you have undoubtedly upgraded my infosec career. Keep doing what you are doing. Hope you continue with videos on this subject matter.

  • @myoaye6225
    @myoaye6225 2 года назад

    The best instruction on SQL injection!

  • @mrsuli1624
    @mrsuli1624 8 месяцев назад

    Mashaallah Sister, I'm proud that I learned from you😊❤

  • @brunocarrazza500
    @brunocarrazza500 3 года назад +2

    Hey Rana! greetings from Brazil!! Thanks for the great work and content you've been putting up. Looking foward to see your next videos!!!

  • @МаксимМельников-ц3п
    @МаксимМельников-ц3п 10 месяцев назад

    Thank you for your knowledge. You are paving the way to knowledge for ordinary people

  • @suryaasurya2350
    @suryaasurya2350 3 года назад +1

    Amazing work. Thanks for providing awesome stuff for free of cost.

  • @GabrielLawrence_gebl
    @GabrielLawrence_gebl 3 года назад +1

    This is great. Thanks for doing it. Shared it with my whole team.

  • @SauravKumar-if4to
    @SauravKumar-if4to Год назад

    Great content given by you for who have not enough money to buy course

  • @xtwisted007x
    @xtwisted007x 3 года назад +2

    I've enjoyed your previous write-ups but this video is sooo stellar!! I've always struggled with getting a good handle on SQLi in the past and mostly just left it up to the automated tools but this guide has given me a much better approach and methodology to apply to injection scenarios. I really appreciate your efforts and look forward to future videos!

    • @RanaKhalil101
      @RanaKhalil101  3 года назад +8

      Thank you! The next 16 videos cover SQLi hands on exercises. By the end of this module, not only will you be become a pro at exploiting SQLi vulnerabilities manually but you'll also learn how to automate the exploitation in python ;)

    • @xtwisted007x
      @xtwisted007x 3 года назад +1

      @@RanaKhalil101 I started thinking about the flow of a python script for this as you were explaining the boolean-based injection. I'm still a python novice however so appreciate learning new methods. 😁

  • @maveronic2868
    @maveronic2868 Год назад +1

    Thank you Rana for your tutorials. Your explanations are clear and concise and I easily grasp these concepts with ease. I have a question about Boolean-Based Blind SQLi. Is it possible that to optimise the finite brute force of each character, the attacker makes use of binary search to find the character, say instead of (…., 1, 1) = ‘s’, the attacker injects (…., 1, 1) < ‘s’, that’d work right?

  • @dhairyanagda1672
    @dhairyanagda1672 3 года назад +4

    Great work! Thank you for doing this. Really means a lot to us beginners❤️ Looking forward to more such informative videos👍

  • @almustaphaawakili1049
    @almustaphaawakili1049 2 года назад

    this is NETCLOUTS you are the best teacher i ever have in the world MAY ALLAH grand you with JANNAH

  • @artistepromotionz9183
    @artistepromotionz9183 3 года назад

    This is the Best Sql explanation on youtube! Keep up the good work👍

  • @syedtajuddin5446
    @syedtajuddin5446 3 года назад +1

    Amazing explanation. very clear and right to the point.

  • @semasema9004
    @semasema9004 Год назад

    Rana, thank you so much for this video! You explain complex topics so simply and clearly! Great!

  • @josekiki1587
    @josekiki1587 3 года назад +2

    The great super explanation I deeply loved it and waiting for more series from you.

  • @haziqamzar5332
    @haziqamzar5332 3 года назад +2

    Assalammualaykum, greetings from Malaysia. There's so much information. Great work! Looking forward next video.

  • @007-AML
    @007-AML 4 месяца назад

    Your voice rhythm made me to watch The way you are teaching was really amazing

  • @CodeXND
    @CodeXND 3 года назад +1

    Thank you for your hard work .. lots of information packed into this video.

  • @andrespino8552
    @andrespino8552 3 года назад

    Wow. This is gold. Thank you very much for taking the time to make this incredible material.

  • @anonymous6666
    @anonymous6666 3 года назад +1

    Oh my goodness. Thanks so much for your hard work, it was super helpful and your video seems professionally made💙

  • @lizardking5303
    @lizardking5303 3 года назад +1

    My new favourite content creator! Thank you so much for this

  • @srlsec
    @srlsec 3 года назад

    Concise and straight to the point

  • @Aditya-xe3de
    @Aditya-xe3de 3 года назад +3

    Really appreciate your efforts and time you put into making these tutorials , these are really helpful and qualitative .also expecting Such more tutorials based on the course ahead . again thank you for sharing your knowledge you're giving back to the community in the amazing way.🙌

  • @Hendrix312002
    @Hendrix312002 3 года назад +1

    This video is incredibly helpful and insightful. I really look forward to the other videos in this series. Thank you!

  • @paco6266
    @paco6266 Год назад

    Buenas tardes Rana, te he conocido gracias a un video que realizaste con David Bombal, y me pareció fantástico y tu super simpatica. Soy una persona normal y corriente, y he tenido recientemente una mala experiencia con una empresa realizando trading, bueno ya te puedes imaginar. Jamás pensé que llegara a ser tan incrédulo. Me gusta mucho como te explicas y lo puedo comprender todo hasta ahora. Nunca es tarde para aprender. Voy a ver que tal empiezo con tus tutoriales y si me llenan como hasta ahora, aportaré al canal de la manera que pueda para que sigamos aprendiendo de tus habilidades.
    Un saludo.

  • @ig101g3
    @ig101g3 3 года назад +2

    Your work is amazing!! I’m excited for more content

  • @janricmalate6793
    @janricmalate6793 3 года назад +1

    Great content, I learned a lot about sqli. I'm looking forward to learn more from your future videos.

  • @haseebnujum636
    @haseebnujum636 3 года назад +1

    Don't stop ur class is ✨️✨️✨️✨️🥳🥳😘

  • @SquareZeroGaming
    @SquareZeroGaming 3 года назад +1

    im glad that i found your channel 1 month ago.. such good content mashallah. keep the contents coming ^_^

  • @CodeWithComments
    @CodeWithComments 3 года назад +2

    Nice tutorial. 👍 I wanna see more tutorials from different topics. 😊

  • @gokuls3931
    @gokuls3931 3 года назад +1

    Loved it.. Pls don't stop this series.. ♥

  • @mystriux5676
    @mystriux5676 3 года назад

    This is amazing. Your video is really easy to understand and I love it! Please continue working on this

  • @gavinLovesMetallica
    @gavinLovesMetallica 3 года назад

    Thank you Rana for helping us learn!!! More power to you!

  • @bobbychase5616
    @bobbychase5616 3 года назад +1

    so much information!
    will be following with the series

  • @chiragagrawal7856
    @chiragagrawal7856 3 года назад

    Thanks for sharing the proper content with us. Your voice makes it more attractive to understand 😊👌

  • @hatab0x
    @hatab0x 2 года назад

    wow I can't get enough of your videos, especially this one

  • @5ql156
    @5ql156 2 года назад

    Thaaank you so much for your videos Rana and the way you make them and time to create them and everything!! much appreciated ♥♥

  • @dripsec
    @dripsec 2 года назад +1

    Thank you so much.your making this so easy to understand

  • @paultidwell8799
    @paultidwell8799 7 месяцев назад

    Thank you, I understand so much better now.

  • @Everything_Anything_For_You
    @Everything_Anything_For_You 3 года назад

    I just wanna say Thank You!. Your videos are awesome.

  • @daniyalahmed7034
    @daniyalahmed7034 3 года назад

    Nicely explained. Great job Rana... Will be following you in entire series.

  • @KyleRichter23
    @KyleRichter23 3 года назад

    I just subscribed. You are very easy to understand and I am excited for more SQL content.

  • @guliver1999
    @guliver1999 3 года назад +1

    Easy to follow explanation. Great presentation! -:)

  • @cybersec-radar
    @cybersec-radar 3 года назад

    Wonderful explanation.... Even kids can understand. Great job.

  • @i_youtube_
    @i_youtube_ 3 года назад

    I like your content. You are great instructor. I like your unique voice too. Thank you so much.

  • @juandaxp3851
    @juandaxp3851 3 года назад +1

    Great work!! Thank you for sharing your knowledge. Looking forward to learning a lot through your channel! :)

  • @RobertJans-e7w
    @RobertJans-e7w 9 месяцев назад

    very interesting, as i've been dealing with such a problem myself (was hacked by ransomware on a university server...) what i don't understand is how you loop over a long hash checking every character: this is classical brute force and should take thousands of years... :)

  • @zubairsafiii
    @zubairsafiii 3 года назад +1

    The way you explain is 🔥🔥

  • @muhammadhasnaatarshad8591
    @muhammadhasnaatarshad8591 2 года назад

    Amazing way of teaching It was very helpful
    Thank you!

  • @EktuTechy
    @EktuTechy 3 года назад +1

    really amazing content.

  • @Blizardde
    @Blizardde 3 года назад +3

    Thanks for the great content.
    One question for me: could you elaborate on Inferential SQLi please?
    how there is no communication established with Server-side or any data-transfer but we get response from DB or Web Application?

    • @RanaKhalil101
      @RanaKhalil101  3 года назад +2

      There is definitely communication with the server-side. What I mentioned in the video, is that there is no direct transfer of data from the database. So unlike Union-based SQLi, I can't simply output the entire hash. Instead, I ask the application true and false questions and based on varying responses in the application, I can infer that the statement that I asked is true or false. Try and solve this lab to learn more about Blind SQLi: portswigger.net/web-security/sql-injection/blind/lab-conditional-responses

    • @Blizardde
      @Blizardde 3 года назад

      @@RanaKhalil101 now it makes sense, thanks for the explanation 🍀🙏

    • @Blizardde
      @Blizardde 3 года назад

      I have three questions:
      1)Do you recommend Securing DevOps: Security in the Cloud to read or WAHH handbook? Which one is better, any comparison pros cons appreciated.
      2) for real world practices, portswigger labs or hackTheBox or hackerone? Pros/Cons? any thoughts
      3) for learning hands-on scripting & automation, what do you suggest?

  • @osaze61
    @osaze61 3 года назад

    Outstanding information, looking forward to continuing the lectures....Thank you

  • @malcrack1
    @malcrack1 2 года назад

    This was awesome content. Thanks for this one. Soon I will enroll in your course in the website.

  • @tourpran
    @tourpran 3 года назад

    wow going to support this channel till the end !!!

  • @jeffreyotega8721
    @jeffreyotega8721 2 года назад +1

    Nice job Rana, welldone ! just to ask, are same videos content available as written materials, like in pdf? thanks a bunch.

  • @RunOs3
    @RunOs3 3 года назад

    Thank you for posting just a great and informative video. I hope all your dreams come true.

  • @nayeemshaik7867
    @nayeemshaik7867 Год назад

    Mam i became fan of your work, please reply to my question, how you are able to manage time in making this many hours of lengthy content with great quality. What is your motivation?❤👍

  • @merazhussain6022
    @merazhussain6022 2 года назад

    What an amzaing content. Your way of explanation is simple yet covers everything. Kudos to youand keep going :)