What is command injection? - Web Security Academy

Поделиться
HTML-код
  • Опубликовано: 23 ноя 2024

Комментарии • 18

  • @HumberNum
    @HumberNum 4 месяца назад +1

    I really love that there is no music in the background, this helps more to concentrate on the video.

  • @Hobby_Technology
    @Hobby_Technology 3 года назад +3

    THANK YOU! I was very stuck on a problem on a ctf for a class I'm in and this saved me.

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 3 года назад +6

    Nicely explained straight to the point does help to find this vulnerability.

  • @mojoxtreme
    @mojoxtreme 3 года назад

    great video, thanks guys!

  • @kezzle9609
    @kezzle9609 2 года назад +6

    idk why you act like you're being held at gunpoint but thanks

    • @amongusboi2032
      @amongusboi2032 Год назад

      Presuming the topic is serious or he has public speaking issues.

  • @igu642
    @igu642 2 года назад +1

    Thank you!

  • @VenkatakrishnanSampath
    @VenkatakrishnanSampath Год назад

    How does a ping/time delay command exploit or retrieve data from the database? In which scenario it is used? if a ping/time delay command is executed, how does it help an attacker?

    • @chritulkas5646
      @chritulkas5646 Год назад

      it just tells to you that the attack was successfull and you can mount different attacks afterwards

  • @true_tamilan
    @true_tamilan 4 года назад

    Great intro info

  • @aarathim7023
    @aarathim7023 4 года назад +1

    Hi sir, i have a doubt.. The command injuction occurs when the program doesn't perform proper input validation, but how could it be possible, we will get a perfect output only if we have a perfect input 🧐but how 🤔.

    • @francescoscotti6189
      @francescoscotti6189 2 года назад +1

      because with injection you run also the correct input, but instead of running just the input, you run other command using the separator ;

    • @The_One_0_0
      @The_One_0_0 2 года назад +1

      That is not the same thing

    • @The_One_0_0
      @The_One_0_0 2 года назад

      Proper input validation is so of u use something such as ; & $ # + ' " etc u could then add on a system command returning the perfect response of the command

    • @The_One_0_0
      @The_One_0_0 2 года назад

      Yea same as what guy before me said

  • @vadon8993
    @vadon8993 Год назад

    THANK YOUUUUUU

  • @johnhack67
    @johnhack67 3 года назад

    Thanks.

  • @joshkindy4826
    @joshkindy4826 3 года назад

    thanks