Basics of SQL Injection - Penetration Testing for Ethical Hackers

Поделиться
HTML-код
  • Опубликовано: 19 дек 2024

Комментарии • 149

  • @kanibeMe
    @kanibeMe 3 года назад +49

    Just wanted to say to everybody at free code camp thank you, my brain needed to settle down and learn a new skill and you guys made that possible I really appreciate it.

  • @pinkninja1410
    @pinkninja1410 3 года назад +37

    Every time I think of something, this channel makes a videos

    • @Shogohod
      @Shogohod 3 года назад +1

      I have same thought 🙂

    • @VLOG-pz7df
      @VLOG-pz7df 3 года назад

      Hey, Can You give me SBVA file?

  • @kennitodevangavani891
    @kennitodevangavani891 3 года назад +98

    Injection, Penetration, Testing...
    Sounds like 2020 & 2021 Covid related stuff 😂 😂 😂 😂
    Thanks FCC

    • @spidermiddleagedman
      @spidermiddleagedman 3 года назад +4

      I just came here to write the same Thing.
      But the First two words reminds me also of something else.

    • @cy_wareye7395
      @cy_wareye7395 3 года назад +1

      Coz its related. Remote work as well

    • @VLOG-pz7df
      @VLOG-pz7df 3 года назад

      @@cy_wareye7395 Man , Can You give me SBVA file?

  • @harshwardhangupta1577
    @harshwardhangupta1577 3 года назад +15

    Great Video .. But learning this all together ..made me understand , I should Sit and Study SQL😂

  • @TheOncher
    @TheOncher 3 года назад +15

    I have literally started learning SQL injection, the day it was uploaded and wondered where can i find a helpfull tutorial to help me, Thank you so much!

  • @420nyk
    @420nyk 2 года назад +3

    Amazing Course. Loved the content. Thanks a lot. Binged the whole thing in 1 shot.

  • @gradientO
    @gradientO 3 года назад +4

    Much more info than I expected. Thanks

  • @gashone
    @gashone 2 года назад +2

    I saw a lot of courses here @ youtube, also pay for other. This explanations are outstanding

  • @mushinart
    @mushinart Год назад +7

    cant find the sbva link .. does not exist ...please help

  • @sureshviswanatham2198
    @sureshviswanatham2198 3 года назад +6

    an excellent video, helped me a lot to understand various SQL injection techniques

    • @VLOG-pz7df
      @VLOG-pz7df 3 года назад +1

      Hey, Can You give me SBVA file?

  • @olabaruwa8287
    @olabaruwa8287 2 года назад

    I was ranting yesterday but I've watched the whole thing and I love it

  • @abdella4
    @abdella4 3 года назад +53

    Whenever I tell ppl I code, this is what they imagine.

  • @mereemail8352
    @mereemail8352 2 года назад +1

    4:10 that number plate is crazy idea💥💥💥💥

  • @lilabare9153
    @lilabare9153 3 года назад +5

    When I tell you I screamed when I saw this in my sub box.....
    let me chill, lol, thanks for this vid! It's been a while since I practiced this and can't wait to go at it again.

  • @subodhbaral8608
    @subodhbaral8608 3 года назад +8

    Hey u r just providing free tech related stuff and it can't be explained in words.Thank you so much

  • @PIDOtomasyon
    @PIDOtomasyon 2 года назад +1

    clever people use Opera :)
    great work, Thank you so much.

  • @shubhambhardwaj891
    @shubhambhardwaj891 3 года назад +4

    Nice course!!!!!

  • @saching24
    @saching24 3 года назад +2

    Thanks for upload the video....🔥🔥🔥

  • @iaor5842
    @iaor5842 3 года назад +1

    Much awaited thanks

  • @rainbowking4097
    @rainbowking4097 3 года назад

    Can't just believe am seeing this kind of file now. Thanks greatly. This is 2021 for me.

  • @matthewdenius
    @matthewdenius Год назад +5

    The course looks great but you've changed where you can access SBVA and now people can't download it.

  • @ndosh1man
    @ndosh1man 2 года назад +1

    This dude made an entire course just to flex his custom number-plated Benz, and I love it!

  • @vinodleo13
    @vinodleo13 2 года назад +4

    hello sir where is the sbva lab
    we can't access

  • @catchmeifyoucan_2024
    @catchmeifyoucan_2024 2 года назад +1

    At 25:15 you mentioned that the website is not using double quotes but how come you were able to login to the website from the command line using double quotes?

  • @capuhodhiambo5059
    @capuhodhiambo5059 11 месяцев назад

    This is the best content. I mean🔥🔥

  • @judeodion
    @judeodion 2 года назад +5

    I am finding it hard to get the sbva file. Has it been removed?
    Any help?

  • @binodgurung3367
    @binodgurung3367 3 года назад +2

    excuse me sir, Here 33:45 you've mention that to find the column we can use bruteforce technique, but isnt the brute force technique used for directly cracking the password of the user using technique like dictionery attack and rainbow table ?

    • @biplabpaneru6834
      @biplabpaneru6834 3 года назад

      no its not,,bruteforce is not actually cracking password ,,,its basically giving number of random or suspected inputs tiil you get the desired results ,,usually its used for password cracking , but you can use for usernames as well,anywhere you need to put specific input to get desired output but u dont know the input then you can try giving random input until u get output, then its a bruteforce,,,for eg if u want to unlock your friends phone but dont know password so u try guessing different pins then it can be called bruteforce,,,dictionary attack is very diffirent in dictionary attack you need to have the hashed or encrypted data. in dictionary attack you need to take random or suspected words and encrypt or hash it then you have to compare with the encrypted or hashed data,, rainbow table attack is same as dictionary attace where rainbow table already have hashed words so you can directly compare the captured file with the hashes

  • @rohanrana2406
    @rohanrana2406 Год назад

    boht acchi video banai hai, sab samajh main aaya. aur zaada samajh main aata agar bhai aap ye fake firangi accent kaa use nhi krtay.

  • @mango-gu5xo
    @mango-gu5xo 2 года назад

    very goooooood video!

  • @sumoninfosec
    @sumoninfosec Год назад +2

    The SBVA file is not on the website, and this individual is not a teacher; rather, he is a fraud. Freecode should remove his video and ban him.

  • @LFSPharaoh
    @LFSPharaoh 3 года назад +14

    Oh wow didn’t know this was still a thing

    • @nameless_9504
      @nameless_9504 3 года назад +1

      It is! Still a thing which stands top of the vulnerability

    • @maven6093
      @maven6093 3 года назад +1

      SQLi, XSS, Broken Authentication, RCE and IDORs the most common bugs currently SQLi being one of the oldest and tbh i don't know much longer it will stay, most likely long more unless some new way to stop is randomly developed out of no where

  • @modjtabagharibyar8632
    @modjtabagharibyar8632 2 года назад +3

    Where is the SBVA file its not avaible on this page

  • @djgulston
    @djgulston 3 года назад

    Very good video, sir! Thank you!

  • @sourav_-_7038
    @sourav_-_7038 3 года назад +1

    ORMs and API based programming pattern will eliminate SQLi not fully, but 90% is done. 10% is good programming skills.

  • @shreyasmehta4528
    @shreyasmehta4528 3 года назад +1

    very good course

    • @VLOG-pz7df
      @VLOG-pz7df 3 года назад

      @@sagarbansal Hey, Can You please
      give me SBVA file?

  • @alanGaMeRhorror
    @alanGaMeRhorror 3 года назад

    Woah very informative, thanks

  • @capomodding
    @capomodding 3 года назад

    Actually very good video to freshen up some knowledge ty for that 👍🏼

  • @skar2564
    @skar2564 3 года назад +2

    Are there any alternatives to the sbva file? (since the sbva link doesn't 'seem to be working anymonre)

  • @dankdreamz8956
    @dankdreamz8956 3 года назад +2

    Thank you 🙏🙏🙏🙏🙏

  • @CodingWorm
    @CodingWorm 3 года назад +5

    If you can't figure this out, don't worry neither can I

  • @atlas42185
    @atlas42185 3 года назад +1

    You guys wouldn't happen to have an XBRL or XML lecture in the works, would you?

  • @mad.d.1673
    @mad.d.1673 2 года назад

    Thank you Sir 👍

  • @BadalKumar-tu2wg
    @BadalKumar-tu2wg 3 года назад

    Very good sir
    Python course Hacking Basis do
    Thanks good video #Useful

  • @catchmeifyoucan_2024
    @catchmeifyoucan_2024 2 года назад

    At 25:43 you have not enclosed 1=1 in single quotes fully like this '1=1' . Are you not supposed to use single quotes to enclose 1=1 ?

  • @abhishekrawat8579
    @abhishekrawat8579 3 года назад +3

    django mein sql injection possible hai?

  • @leviyt2500
    @leviyt2500 10 месяцев назад +1

    i think you have removed the sbva from your website cant find it

  • @tahmidamit5578
    @tahmidamit5578 3 года назад

    This dude's flexing everything.

  • @numberonegeekstudios9657
    @numberonegeekstudios9657 2 года назад +3

    The sbva isnt on the server anymore

  • @TheMrInnokenty
    @TheMrInnokenty 3 года назад +1

    I just added Learn about SQLI in my todo list, and then FCC hacked my laptop and made this course)

    • @tera_hz7125
      @tera_hz7125 3 года назад +1

      My phone is also a victim of this hack lol

    • @tera_hz7125
      @tera_hz7125 3 года назад

      @@sagarbansal oh mind heckar

  • @numberonegeekstudios9657
    @numberonegeekstudios9657 2 года назад +1

    how can i download the sbva application

  • @sumedh1678
    @sumedh1678 3 года назад +2

    Next video should be for cross site scripting.

  • @themultiverse101-o2x
    @themultiverse101-o2x 2 года назад +1

    @Sagar Bansal can you plz update the link....

  • @mohammed.junaidd
    @mohammed.junaidd 2 года назад

    when we are giving username as input and when it matches with the database it show the stuff of given username but by sql injection we are not providing the username so how its login with that username and show stuff of that username

  • @hiddahax
    @hiddahax 2 года назад

    Great Course 🔥
    Thank you ❤️

  • @sarthakchauhan6026
    @sarthakchauhan6026 3 года назад +2

    नमस्ते,he is indian

  • @DigitalTrendzy2023
    @DigitalTrendzy2023 3 года назад

    Any training are you providing sir bansalji

  • @sravanthogari3902
    @sravanthogari3902 3 года назад

    Hello sir , can you tell me the lab setup for the 32 bit

  • @djmostephens
    @djmostephens 3 года назад +4

    Can't download sbva

  • @bridgeboo3031
    @bridgeboo3031 3 года назад

    thanks for the video but could you add a dB limiter next video cause my ears have are sensitive for sudden loud sounds and somehow this video has alot so i had to keep it at a lower volume

    • @altoclef4989
      @altoclef4989 3 года назад

      I don't know if you are on desktop or mobile, but I know there are browser extensions for decibel limiters out there

  • @ye3209
    @ye3209 3 года назад +1

    The link can't get me the lab files Sagar.

  • @mod_cyber1015
    @mod_cyber1015 3 года назад +2

    Why injection is always scary.

  • @nirbhaykumarchaubey8777
    @nirbhaykumarchaubey8777 Год назад

    This works!!!

  • @MDSOHAIL-vq6lb
    @MDSOHAIL-vq6lb 2 года назад +1

    link for sbva is broken

  • @yasser7077
    @yasser7077 3 года назад +1

    SQL is used along side with Python ?

    • @yasser7077
      @yasser7077 3 года назад

      @@sagarbansal THANKS A LOT

    • @nameless_9504
      @nameless_9504 3 года назад

      Not python but django or flask which python frame work

    • @VLOG-pz7df
      @VLOG-pz7df 3 года назад

      @@yasser7077 Hey, Can You give me SBVA file?

  • @engenglish610
    @engenglish610 3 года назад +1

    There is any problem, I can't download this video ?

  • @BobF510
    @BobF510 Год назад

    Truly remarkable content. A similar book I delved into was a game changer. "Game Theory and the Pursuit of Algorithmic Fairness" by Jack Frostwell

  • @mohaneesh-tech
    @mohaneesh-tech 3 года назад +1

    could you please update the sbva lab file

  • @ankitjadhav4890
    @ankitjadhav4890 3 года назад

    One question?? Here can we learn to access anyones android or ios systems?? With linux or anything?

  • @ahmeddjebabla766
    @ahmeddjebabla766 Год назад

    think you so match I need ulr for sbva please

  • @gilbertndekwa691
    @gilbertndekwa691 2 года назад

    hello sir I can,t access the sbva lab, kindly assist

  • @anant-strong
    @anant-strong 3 года назад

    Please complete devops

  • @sunilrai5506
    @sunilrai5506 3 года назад

    hello sir how to know which SQL injection can exploit
    any tips for us sir
    if yes, please help

  • @samindunimsara
    @samindunimsara 3 года назад +2

    Can't download lab file why

  • @AlexCyber-t8m
    @AlexCyber-t8m 6 месяцев назад

    I cant access using " or 1=1# cuz the type isn't username but email address

  • @emm5752
    @emm5752 3 года назад

    hi, i can't download the lab file.could you please assist me?I urgently need to learn this course.

  • @normalhumanbeing6066
    @normalhumanbeing6066 3 года назад +10

    this is not gonna age well

    • @TonyShasta
      @TonyShasta 2 года назад

      Yeah, for real. Abandoned ;(

  • @dariusboteand7722
    @dariusboteand7722 3 года назад +1

    Man your links don't get anywhere.... i think you need to review them

  • @krutiknikhal
    @krutiknikhal 2 года назад

    Cannot access sbva site..can anyine help with lab file please

    • @gilbertndekwa691
      @gilbertndekwa691 2 года назад

      did you manage to download the file? If yes, kindly share

  • @WtfAnupam
    @WtfAnupam 2 года назад

    the lecture was pretty amazing, but IDK what's wrong with your accent!

  • @umashankar-uu9cu
    @umashankar-uu9cu 3 года назад

    should I learn SQL programming before learning sql injection

    • @luc8386
      @luc8386 3 года назад +1

      Yes, it will make the concepts of sql injection easy to understand

  • @Rs3Audi
    @Rs3Audi 3 года назад +1

    Your webapp won't getting SQL Injection if you only host at 127.0.0.1

  • @Rs3Audi
    @Rs3Audi 3 года назад

    Watched the whole video, hope i can hack NASA someday

  • @e281tangy
    @e281tangy 3 года назад

    site not live anymore... wonder what happened..

  • @cybertools8560
    @cybertools8560 3 года назад

    Listen to the intro in x2 speed.
    Me: Vuuuuut???

  • @nagarajaseshadri6498
    @nagarajaseshadri6498 3 года назад +1

    please provide the files in SVBA

  • @BillyMahmood
    @BillyMahmood 3 года назад +1

    Who still writes code like this? Please use a framework like Laravel and encrypt your passwords

    • @BillyMahmood
      @BillyMahmood 3 года назад

      @@sagarbansal I would love to see you carry out the same techniques for a Laravel project or Symfony project using their built in auth package

    • @BillyMahmood
      @BillyMahmood 3 года назад

      @@sagarbansal lol Laravel 5.4? You know they are on version 8 now right?

    • @temitopehardhekheyhe7359
      @temitopehardhekheyhe7359 3 года назад +1

      @@BillyMahmood
      Laravel developers do dumber things than this am afraid …
      do you know how many times I've seen a Laravel built site spit out config information or reveal! source! code! because of an unhandled error!! of some sort? … there's still one I came across last week that I haven't reported yet, and the site is professionally coded in all sense, and has thousands! of monthly users! … now anytime a developer/lead tells me "oh we used Laravel to handle all that" I am much more optimistic that I would find something that will go wrong than when they say "Oh we did our backend in Django", because I've come to understand that when it comes to Laravel there's a hundred ways to shoot yourself in the foot.
      unfortunately, that has given me a bias, now I don't recommend Laravel to clients, not because Laravel is insecure, but because finding decent or security conscious Laravel developers is not easy!, compare to Django that will not let you do some things by default, and less ways to mess things up, and even if you mess things up, default errors are not as verbose as revealing source code or spitting out config files!!!.
      Sorry for the long story!!.

    • @BillyMahmood
      @BillyMahmood 3 года назад

      @@temitopehardhekheyhe7359 Yeh

    • @temitopehardhekheyhe7359
      @temitopehardhekheyhe7359 3 года назад

      @@BillyMahmood
      waaay beyond getting triggered though

  • @elwiswo
    @elwiswo 2 года назад

    16:41

  • @trickshot8653
    @trickshot8653 3 года назад

    Why sqlmap didnt work the first time

  • @haanrey
    @haanrey 2 года назад

    35:58

  • @medhababar9873
    @medhababar9873 3 года назад +1

    Sir I want a course on RUclips clone with react js

  • @kestup5927
    @kestup5927 3 года назад +2

    Ahh I'll rather use sqlmap

  • @klarnorbert
    @klarnorbert 3 года назад +2

    Looks like pen testing tutorials didn't chang in the last 10 years. lmao

  • @abinesha4204
    @abinesha4204 3 года назад

    E commerce website pdf link send

  • @pho3_nix
    @pho3_nix 2 года назад

    the lab file doesnt exist

  • @0m3n1t0
    @0m3n1t0 3 года назад

    No lab file anymore, web goes as landing page and it offers to pay money for your lessons... bad move bro

  • @tanned_cosines_
    @tanned_cosines_ 3 года назад

    XSS attack's basics PWWWESE

  • @roguekelvin8508
    @roguekelvin8508 2 года назад

    your website is not working

  • @golamrabby6911
    @golamrabby6911 3 года назад

    what is this

  • @sarcasticdna
    @sarcasticdna 3 года назад

    I hacked nasa using HTML5, yeah