SQLi WAF Bypass Techniques Part 1 - Time-Based Attacks

Поделиться
HTML-код
  • Опубликовано: 17 июн 2024
  • We will explore the various methods on how you can use a Time-Based SQL injection attack on WAF hardened website. This is part 1 of SQL injection WAF bypasses. If you are interested in Union, Error, or Boolean WAF bypasses, you will see it in part 2:
    • SQLi WAF Bypass Techni...
    ---
    Patreon: ott3rly.com/patreon
    Twitter: ott3rly.com/twitter
    Discord: ott3rly.com/discord
    Get a $200, 60-day credit for DigitalOcean: ott3rly.com/do
    NordVPN: ott3rly.com/NordVPN
    Domain: ott3rly.com/123-reg-co-uk
    Disclaimer: This channel is strictly educational for learning about ethical hacking and penetration testing so that we can protect ourselves against real hackers. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment.
    #bugbounty #ethicalhacking #infosec #cybersecurity #itsecurity
  • НаукаНаука

Комментарии • 30

  • @Free.Education786
    @Free.Education786 Месяц назад +2

    Thanks, Boss.
    👌💉♥️🔥💫💥💢💯🥇👍✅️✔️🤝
    Please, if possible, cover these important topics.
    1. How to discover hidden subdomains of subdomains.
    2. How to delete out of scope and dead Subdomains.
    3. How to crawl all subdomains to discover hidden endpoints and parameters to pipe them in SQLMAP and GHAURI.
    4. How to bypass WAF using SQLMAP and GHAURI.
    5. How to try time based blind SQL injection 💉 using http request headers.
    6. How to write custom http request headers for XOR encoded time based blind SQL injection 💉.
    7. How find website origin IP ❤

    • @Free.Education786
      @Free.Education786 24 дня назад

      Thanks, Boss, 👌💯✅️✔️🔥♥️✌️🤝✈️❤️

  • @naumanalam5572
    @naumanalam5572 Месяц назад +2

    Best part is live waf bypass.
    Share a video on live web app to look for Boolean SQLi.

    • @Ott3rly
      @Ott3rly  Месяц назад +1

      Thanks for the suggestions. I will think about it ;)

  • @prob_here
    @prob_here Месяц назад +2

    Nice

  • @deepakpatidar9303
    @deepakpatidar9303 Месяц назад +2

    This is another great video, i am really want to be your student all time ❤

    • @Ott3rly
      @Ott3rly  Месяц назад

      Wow, thank you!

  • @0xrohit54
    @0xrohit54 Месяц назад +2

    Awesome explanation with Live Practical🔥

  • @shahid.aaqeel
    @shahid.aaqeel Месяц назад +2

    Man you're the best

  • @Usmaini-ku7lq
    @Usmaini-ku7lq 10 дней назад +1

    Good

  • @jamesmckee9017
    @jamesmckee9017 Месяц назад +2

    Let's GOOOOO!

  • @saYOn-tj7xq
    @saYOn-tj7xq Месяц назад +2

    can you show us how did you set up that WAF lab ! and thanks for the amazing video :)

    • @Ott3rly
      @Ott3rly  Месяц назад

      Good idea, I might do this in the future.

  • @user-pj1zb3yz2i
    @user-pj1zb3yz2i Месяц назад +3

    Bro recon part 2

    • @Ott3rly
      @Ott3rly  Месяц назад +3

      Next week. Be patient ;)

  • @writecode9932
    @writecode9932 Месяц назад +2

    Bro, can you make a video about your browser extensions and their use, looks some nice extensions are there.

    • @Ott3rly
      @Ott3rly  Месяц назад +2

      Not sure about separate video, but I could mention this on following live video ;)

    • @writecode9932
      @writecode9932 Месяц назад +1

      @@Ott3rly 😎

  • @Free.Education786
    @Free.Education786 Месяц назад +1

    Part2 link ? Please. Thanks 🎉❤💢💯🥇👌💉♥️✅️🔥✔️💫🤝💥❤️

    • @Ott3rly
      @Ott3rly  28 дней назад +1

      Will add that to description soon

  • @jutapengaming5438
    @jutapengaming5438 Месяц назад +1

    Is this a step for beginners?

  • @mdjeionmia4118
    @mdjeionmia4118 Месяц назад +1

    Any tool for automatic temper check?

    • @Ott3rly
      @Ott3rly  Месяц назад +2

      There are multiple ones on Github, but to be honest they haven't worked me that much that I would be 100% comfortable to recommend one.

    • @Free.Education786
      @Free.Education786 Месяц назад +2

      Atlas. It can suggest the best tamper script to bypass specific WAF. Thanks

  • @iloiskihailm8710
    @iloiskihailm8710 Месяц назад +2

    keep them nuggets comin' (^///^)(^///^)

  • @aanyt5755
    @aanyt5755 Месяц назад +1

    Broh idor topic

    • @Ott3rly
      @Ott3rly  Месяц назад +1

      I might do some CTFs in the future and explain how to hunt those ;)