Advanced SQL Injection - (TryHackMe!)

Поделиться
HTML-код
  • Опубликовано: 31 янв 2025

Комментарии • 11

  • @tomdotsh
    @tomdotsh 3 месяца назад

    Man, thanks for this, i had trouble with the last SQLi attempt using the user agent hehe

  • @GrayCubist
    @GrayCubist 7 месяцев назад

    Great video, love that your curiosity makes you try more than what the room creator intended.

  • @tedsprogz
    @tedsprogz 7 месяцев назад

    on update.php, none of the input fields have input validation...no 2nd order needed

  • @mustyrious
    @mustyrious 2 месяца назад

    1:13:17 Yo bro please respond i got two questions, why didn't you do it in the terminal would it still work curl -H "User-Agent: ' UNION SELECT...., and for the why is flag? Why wouldnt it be WHERE book_id = '1'?
    Am i slow?

    • @Macj707
      @Macj707 День назад

      no they said book_id=1 but we just ignored that and did the union with
      book_id, flag
      so it was union select * from those columns from the table books
      so it dumped everything and we grab the flag... it just wasn't necessary

  • @charlesnathansmith
    @charlesnathansmith 7 месяцев назад

    One of the original language specs was adamant that it's pronounced S-Q-L, because they had started calling it SEQUEL but were threatened with a lawsuit from another company that had already trademarked the name

  • @GilligansTravels
    @GilligansTravels 7 месяцев назад

    right on thanks Tyler

  • @jjjww975
    @jjjww975 3 месяца назад +1

    I had to use tun0 IP on my Parrot OS box to drop the out.txt

  • @survivingkampala6010
    @survivingkampala6010 6 месяцев назад

    Can’t find the notes 😢

  • @Macj707
    @Macj707 День назад

    CHEF WUZ HERE!

  • @mustyrious
    @mustyrious 2 месяца назад

    Its highlighted i think Im slow