Basics of SQL Injection - Penetration Testing for Ethical Hackers

Поделиться
HTML-код
  • Опубликовано: 25 июл 2024
  • SQL injection is a common hacking technique used to retrieve or destroy data from a database without permission. It is considered one of the top web application security risks.
    In this course, you will learn how SQL injection works so you are able to defended against this hacker attack in your own web applications.
    ✏️ This course was developed by Sagar Bansal. Check out his channel: / @sagarbansal
    ⭐️ Course Contents ⭐️
    ⌨️ (0:00:00) Introduction
    ⌨️ (0:02:33) What is SQL Injection
    ⌨️ (0:06:56) Lab Setup
    ⌨️ (0:11:04) Basics of SQL
    ⌨️ (0:16:33) Classic Injection Bypass
    ⌨️ (0:26:01) Types of SQL Injection
    ⌨️ (0:30:21) Union Based SQL Injection
    ⌨️ (0:41:08) Error Based SQL Injection
    ⌨️ (0:53:27) Boolean Based SQL Injection
    ⌨️ (1:03:04) Time-Based SQL Injection
    ⌨️ (1:11:39) Semi-Automated SQL Injection
    ⌨️ (1:24:02) Fully Automated SQL Injection
    ⌨️ (1:37:11) Defending Against SQL Injections
    --
    Learn to code for free and get a developer job: www.freecodecamp.org
    Read hundreds of articles on programming: freecodecamp.org/news

Комментарии • 153

  • @kanibeMe
    @kanibeMe 3 года назад +49

    Just wanted to say to everybody at free code camp thank you, my brain needed to settle down and learn a new skill and you guys made that possible I really appreciate it.

  • @pinkninja1410
    @pinkninja1410 3 года назад +36

    Every time I think of something, this channel makes a videos

    • @Shogohod
      @Shogohod 3 года назад +1

      I have same thought 🙂

    • @VLOG-pz7df
      @VLOG-pz7df 2 года назад

      Hey, Can You give me SBVA file?

  • @abdella4
    @abdella4 3 года назад +53

    Whenever I tell ppl I code, this is what they imagine.

  • @mushinart
    @mushinart Год назад +7

    cant find the sbva link .. does not exist ...please help

  • @420nyk
    @420nyk 2 года назад +3

    Amazing Course. Loved the content. Thanks a lot. Binged the whole thing in 1 shot.

  • @gradientO
    @gradientO 3 года назад +4

    Much more info than I expected. Thanks

  • @harshwardhangupta1577
    @harshwardhangupta1577 3 года назад +15

    Great Video .. But learning this all together ..made me understand , I should Sit and Study SQL😂

  • @kennitodevangavani891
    @kennitodevangavani891 3 года назад +96

    Injection, Penetration, Testing...
    Sounds like 2020 & 2021 Covid related stuff 😂 😂 😂 😂
    Thanks FCC

    • @spidermiddleagedman
      @spidermiddleagedman 3 года назад +4

      I just came here to write the same Thing.
      But the First two words reminds me also of something else.

    • @cy_wareye7395
      @cy_wareye7395 3 года назад +1

      Coz its related. Remote work as well

    • @VLOG-pz7df
      @VLOG-pz7df 2 года назад

      @@cy_wareye7395 Man , Can You give me SBVA file?

  • @gashone
    @gashone 2 года назад +2

    I saw a lot of courses here @ youtube, also pay for other. This explanations are outstanding

  • @saching24
    @saching24 3 года назад +2

    Thanks for upload the video....🔥🔥🔥

  • @lilabare9153
    @lilabare9153 3 года назад +5

    When I tell you I screamed when I saw this in my sub box.....
    let me chill, lol, thanks for this vid! It's been a while since I practiced this and can't wait to go at it again.

  • @djgulston
    @djgulston 3 года назад

    Very good video, sir! Thank you!

  • @iaor5842
    @iaor5842 3 года назад +1

    Much awaited thanks

  • @capomodding
    @capomodding 2 года назад

    Actually very good video to freshen up some knowledge ty for that 👍🏼

  • @sureshviswanatham2198
    @sureshviswanatham2198 3 года назад +6

    an excellent video, helped me a lot to understand various SQL injection techniques

    • @VLOG-pz7df
      @VLOG-pz7df 2 года назад +1

      Hey, Can You give me SBVA file?

  • @shubhambhardwaj891
    @shubhambhardwaj891 3 года назад +4

    Nice course!!!!!

  • @olabaruwa8287
    @olabaruwa8287 Год назад

    I was ranting yesterday but I've watched the whole thing and I love it

  • @rainbowking4097
    @rainbowking4097 3 года назад

    Can't just believe am seeing this kind of file now. Thanks greatly. This is 2021 for me.

  • @alanGaMeRhorror
    @alanGaMeRhorror 3 года назад

    Woah very informative, thanks

  • @vinodleo13
    @vinodleo13 2 года назад +4

    hello sir where is the sbva lab
    we can't access

  • @PIDOtomasyon
    @PIDOtomasyon 2 года назад +1

    clever people use Opera :)
    great work, Thank you so much.

  • @matthewdenius
    @matthewdenius Год назад +4

    The course looks great but you've changed where you can access SBVA and now people can't download it.

  • @judeodion
    @judeodion 2 года назад +5

    I am finding it hard to get the sbva file. Has it been removed?
    Any help?

  • @modjtabagharibyar8632
    @modjtabagharibyar8632 Год назад +3

    Where is the SBVA file its not avaible on this page

  • @dankdreamz8956
    @dankdreamz8956 3 года назад +2

    Thank you 🙏🙏🙏🙏🙏

  • @mereemail8352
    @mereemail8352 Год назад +1

    4:10 that number plate is crazy idea💥💥💥💥

  • @TheOncher
    @TheOncher 3 года назад +14

    I have literally started learning SQL injection, the day it was uploaded and wondered where can i find a helpfull tutorial to help me, Thank you so much!

  • @Hashtagfindgavin
    @Hashtagfindgavin 3 года назад

    Thanks!

  • @mad.d.1673
    @mad.d.1673 Год назад

    Thank you Sir 👍

  • @atlas42185
    @atlas42185 3 года назад +1

    You guys wouldn't happen to have an XBRL or XML lecture in the works, would you?

  • @subodhbaral8608
    @subodhbaral8608 3 года назад +8

    Hey u r just providing free tech related stuff and it can't be explained in words.Thank you so much

  • @mango-gu5xo
    @mango-gu5xo 2 года назад

    very goooooood video!

  • @skar2564
    @skar2564 2 года назад +2

    Are there any alternatives to the sbva file? (since the sbva link doesn't 'seem to be working anymonre)

  • @LFSPharaoh
    @LFSPharaoh 3 года назад +14

    Oh wow didn’t know this was still a thing

    • @nameless_9504
      @nameless_9504 3 года назад +1

      It is! Still a thing which stands top of the vulnerability

    • @maven6093
      @maven6093 3 года назад +1

      SQLi, XSS, Broken Authentication, RCE and IDORs the most common bugs currently SQLi being one of the oldest and tbh i don't know much longer it will stay, most likely long more unless some new way to stop is randomly developed out of no where

  • @capuhodhiambo5059
    @capuhodhiambo5059 6 месяцев назад

    This is the best content. I mean🔥🔥

  • @catchmeifyoucan_2024
    @catchmeifyoucan_2024 Год назад +1

    At 25:15 you mentioned that the website is not using double quotes but how come you were able to login to the website from the command line using double quotes?

  • @numberonegeekstudios9657
    @numberonegeekstudios9657 Год назад +3

    The sbva isnt on the server anymore

  • @ndosh1man
    @ndosh1man 2 года назад +1

    This dude made an entire course just to flex his custom number-plated Benz, and I love it!

  • @Icetornyt
    @Icetornyt 3 года назад +1

    Mug shot like a superstar :D

  • @engenglish610
    @engenglish610 3 года назад +1

    There is any problem, I can't download this video ?

  • @hiddahax4821
    @hiddahax4821 2 года назад

    Great Course 🔥
    Thank you ❤️

  • @sravanthogari3902
    @sravanthogari3902 2 года назад

    Hello sir , can you tell me the lab setup for the 32 bit

  • @djmostephens
    @djmostephens 3 года назад +4

    Can't download sbva

  • @mohammed.junaidd
    @mohammed.junaidd 2 года назад

    when we are giving username as input and when it matches with the database it show the stuff of given username but by sql injection we are not providing the username so how its login with that username and show stuff of that username

  • @shreyasmehta4528
    @shreyasmehta4528 3 года назад +1

    very good course

    • @VLOG-pz7df
      @VLOG-pz7df 2 года назад

      @@sagarbansal Hey, Can You please
      give me SBVA file?

  • @HackingInSeconds
    @HackingInSeconds 2 года назад +1

    @Sagar Bansal can you plz update the link....

  • @emm5752
    @emm5752 2 года назад

    hi, i can't download the lab file.could you please assist me?I urgently need to learn this course.

  • @binodgurung3367
    @binodgurung3367 3 года назад +2

    excuse me sir, Here 33:45 you've mention that to find the column we can use bruteforce technique, but isnt the brute force technique used for directly cracking the password of the user using technique like dictionery attack and rainbow table ?

    • @biplabpaneru6834
      @biplabpaneru6834 2 года назад

      no its not,,bruteforce is not actually cracking password ,,,its basically giving number of random or suspected inputs tiil you get the desired results ,,usually its used for password cracking , but you can use for usernames as well,anywhere you need to put specific input to get desired output but u dont know the input then you can try giving random input until u get output, then its a bruteforce,,,for eg if u want to unlock your friends phone but dont know password so u try guessing different pins then it can be called bruteforce,,,dictionary attack is very diffirent in dictionary attack you need to have the hashed or encrypted data. in dictionary attack you need to take random or suspected words and encrypt or hash it then you have to compare with the encrypted or hashed data,, rainbow table attack is same as dictionary attace where rainbow table already have hashed words so you can directly compare the captured file with the hashes

  • @CodingWorm
    @CodingWorm 3 года назад +5

    If you can't figure this out, don't worry neither can I

  • @DigitalTrendzy2023
    @DigitalTrendzy2023 3 года назад

    Any training are you providing sir bansalji

  • @BadalKumar-tu2wg
    @BadalKumar-tu2wg 2 года назад

    Very good sir
    Python course Hacking Basis do
    Thanks good video #Useful

  • @numberonegeekstudios9657
    @numberonegeekstudios9657 Год назад +1

    how can i download the sbva application

  • @sunilrai5506
    @sunilrai5506 2 года назад

    hello sir how to know which SQL injection can exploit
    any tips for us sir
    if yes, please help

  • @ye3209
    @ye3209 2 года назад +1

    The link can't get me the lab files Sagar.

  • @sumedh1678
    @sumedh1678 3 года назад +2

    Next video should be for cross site scripting.

  • @anant-strong
    @anant-strong 3 года назад

    Please complete devops

  • @nirbhaykumarchaubey8777
    @nirbhaykumarchaubey8777 Год назад

    This works!!!

  • @mohaneesh-tech
    @mohaneesh-tech 2 года назад +1

    could you please update the sbva lab file

  • @ahmeddjebabla766
    @ahmeddjebabla766 11 месяцев назад

    think you so match I need ulr for sbva please

  • @TheAmubis
    @TheAmubis 3 года назад +2

    Thanks, codecamp.
    I've been listening while practicing a good chunk of coding tutorial, primarily the hacking one in this channel all over quarantine but still left clueless what to do with this. I guess I'm just having minus IQ.

  • @rohanrana2406
    @rohanrana2406 Год назад

    boht acchi video banai hai, sab samajh main aaya. aur zaada samajh main aata agar bhai aap ye fake firangi accent kaa use nhi krtay.

  • @gilbertndekwa691
    @gilbertndekwa691 Год назад

    hello sir I can,t access the sbva lab, kindly assist

  • @bridgeboo3031
    @bridgeboo3031 3 года назад

    thanks for the video but could you add a dB limiter next video cause my ears have are sensitive for sudden loud sounds and somehow this video has alot so i had to keep it at a lower volume

    • @altoclef4989
      @altoclef4989 2 года назад

      I don't know if you are on desktop or mobile, but I know there are browser extensions for decibel limiters out there

  • @MDSOHAIL-vq6lb
    @MDSOHAIL-vq6lb 2 года назад +1

    link for sbva is broken

  • @Rs3Audi
    @Rs3Audi 3 года назад +1

    Your webapp won't getting SQL Injection if you only host at 127.0.0.1

  • @leviyt2500
    @leviyt2500 5 месяцев назад +1

    i think you have removed the sbva from your website cant find it

  • @mod_cyber1015
    @mod_cyber1015 3 года назад +2

    Why injection is always scary.

  • @user-db3wf3vr6b
    @user-db3wf3vr6b Месяц назад

    I cant access using " or 1=1# cuz the type isn't username but email address

  • @tahmidamit5578
    @tahmidamit5578 3 года назад

    This dude's flexing everything.

  • @abhishekrawat8579
    @abhishekrawat8579 3 года назад +3

    django mein sql injection possible hai?

  • @BobF510
    @BobF510 9 месяцев назад

    Truly remarkable content. A similar book I delved into was a game changer. "Game Theory and the Pursuit of Algorithmic Fairness" by Jack Frostwell

  • @catchmeifyoucan_2024
    @catchmeifyoucan_2024 Год назад

    At 25:43 you have not enclosed 1=1 in single quotes fully like this '1=1' . Are you not supposed to use single quotes to enclose 1=1 ?

  • @e281tangy
    @e281tangy 2 года назад

    site not live anymore... wonder what happened..

  • @nagarajaseshadri6498
    @nagarajaseshadri6498 2 года назад +1

    please provide the files in SVBA

  • @ankitjadhav4890
    @ankitjadhav4890 3 года назад

    One question?? Here can we learn to access anyones android or ios systems?? With linux or anything?

  • @sourav_-_7038
    @sourav_-_7038 3 года назад +1

    ORMs and API based programming pattern will eliminate SQLi not fully, but 90% is done. 10% is good programming skills.

  • @sarthakchauhan6026
    @sarthakchauhan6026 3 года назад +2

    नमस्ते,he is indian

  • @samindunimsara
    @samindunimsara 3 года назад +2

    Can't download lab file why

  • @dariusboteand7722
    @dariusboteand7722 2 года назад +1

    Man your links don't get anywhere.... i think you need to review them

  • @normalhumanbeing6066
    @normalhumanbeing6066 3 года назад +10

    this is not gonna age well

    • @TonyShasta
      @TonyShasta Год назад

      Yeah, for real. Abandoned ;(

  • @TheMrInnokenty
    @TheMrInnokenty 3 года назад +1

    I just added Learn about SQLI in my todo list, and then FCC hacked my laptop and made this course)

    • @tera_hz7125
      @tera_hz7125 3 года назад +1

      My phone is also a victim of this hack lol

    • @tera_hz7125
      @tera_hz7125 3 года назад

      @@sagarbansal oh mind heckar

  • @krutiknikhal
    @krutiknikhal 2 года назад

    Cannot access sbva site..can anyine help with lab file please

    • @gilbertndekwa691
      @gilbertndekwa691 Год назад

      did you manage to download the file? If yes, kindly share

  • @Rs3Audi
    @Rs3Audi 3 года назад

    Watched the whole video, hope i can hack NASA someday

  • @yasser7077
    @yasser7077 3 года назад +1

    SQL is used along side with Python ?

    • @yasser7077
      @yasser7077 3 года назад

      @@sagarbansal THANKS A LOT

    • @nameless_9504
      @nameless_9504 3 года назад

      Not python but django or flask which python frame work

    • @VLOG-pz7df
      @VLOG-pz7df 2 года назад

      @@yasser7077 Hey, Can You give me SBVA file?

  • @trickshot8653
    @trickshot8653 2 года назад

    Why sqlmap didnt work the first time

  • @umashankar-uu9cu
    @umashankar-uu9cu 3 года назад

    should I learn SQL programming before learning sql injection

    • @luc8386
      @luc8386 3 года назад +1

      Yes, it will make the concepts of sql injection easy to understand

  • @medhababar9873
    @medhababar9873 3 года назад +1

    Sir I want a course on RUclips clone with react js

  • @abinesha4204
    @abinesha4204 3 года назад

    E commerce website pdf link send

  • @cybertools8560
    @cybertools8560 3 года назад

    Listen to the intro in x2 speed.
    Me: Vuuuuut???

  • @pho3_nix
    @pho3_nix 2 года назад

    the lab file doesnt exist

  • @aog3962
    @aog3962 3 года назад +2

    1st

  • @golamrabby6911
    @golamrabby6911 3 года назад

    what is this

  • @elwiswo
    @elwiswo Год назад

    16:41

  • @kestup5927
    @kestup5927 3 года назад +2

    Ahh I'll rather use sqlmap

  • @roguekelvin8508
    @roguekelvin8508 2 года назад

    your website is not working

  • @himansh0715
    @himansh0715 2 года назад

    the lecture was pretty amazing, but IDK what's wrong with your accent!

  • @haanrey
    @haanrey 2 года назад

    35:58

  • @tanned_cosines_
    @tanned_cosines_ 3 года назад

    XSS attack's basics PWWWESE

  • @sumoninfosec
    @sumoninfosec Год назад +2

    The SBVA file is not on the website, and this individual is not a teacher; rather, he is a fraud. Freecode should remove his video and ban him.