Live Hacking: SQL Injection For Beginners (Part 1)

Поделиться
HTML-код
  • Опубликовано: 9 июл 2024
  • Sign up for Snyk for free: snyk.co/techraj
    Some useful resources on SQL Injection:
    snyk.io/blog/sql-injection-ch...
    snyk.io/learn/sql-injection/
    snyk.io/blog/sql-injection-or...
    DISCLAIMER: The demonstration shown in this video is
    performed in a controlled lab setup. This video
    is for educational purposes only. You can only
    perform penetration testing in your own lab
    environment and doing it on any live application
    is not allowed and it is a crime unless you are a
    professional and have appropriate permissions.
    In this video, I demonstrated Error-based SQL Injection and by demonstrating it practically on an intentionally vulnerable application called Juice Shop.
    OWASP Juice Shop is probably the most modern and sophisticated insecure web application! It can be used in security trainings, awareness demos, CTFs and as a guinea pig for security tools! Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications!
    In this video, we exploit the SQLI vulnerability on Juice Shop
    Juice Shop: github.com/bkimminich/juice-shop
    You can run juice shop on your computer by simply using Docker (check out the above link to read the instructions on how to do so)
    Originally, this video was supposed to contain both Error-based SQLI and Blind SQLI, but since the video is getting very long, I had to split it into two parts. This is part 1 that has the Error-based SQLI demo, the part 2 will have the Blind SQLI demo.
    I uploaded part 2 to Odysee (LBRY based app) to support the cause of decentralizing the web. Decentralization means no censorship and content freedom!
    Unlike platforms like RUclips (which are biased and controlled by a central authority), decentralized applications are not controlled by any single authority, no one has excessive powers or privileges over these applications, and most importantly they are also open-source so no data theft!
    This is why I believe the decentralized web is the future!
    Learn more about LBRY (a content-sharing decentralized application): lbry.com/
    Watch Part 2 on Odysee: odysee.com/@techraj156:4/sql-...
    If you are new to Odysee, you can use my link to signup: odysee.com/$/invite/@techraj1...
    Chapters:
    0:00 Disclaimer & What are we going to learn in this video?
    1:31 About our sponsors - Snyk
    5:06 What is SQL?
    5:57 What is SQL Injection?
    7:06 SQL Injection on Juice Shop
    7:37 Install Juice Shop on your PC with Docker
    10:22 Exploiting SQL Injection in the Login feature
    18:20 Exploiting SQL Injection in the Search feature
    34:39 Using SQL Map to automate SQL Injection
    39:35 Error based SQLI vs Blind SQLI
    40:31 Using Snyk to find and fix SQL Injection bugs
    50:31 End of Part 1
    Thanks for watching!
    SUBSCRIBE FOR MORE VIDEOS!
    Join my Discord: / discord
    Follow me on Instagram: / teja.techraj​​​​​
    Website: techraj156.com​​​​​
    Blog: blog.techraj156.com​
  • НаукаНаука

Комментарии • 264

  • @TechRaj156
    @TechRaj156  3 года назад +35

    Watch part 2 on Odysee (LBRY based decentralized content-sharing application): odysee.com/@techraj156:4/sql-injection-part2
    Also, check out Snyk: snyk.co/techraj

    • @bdas8420
      @bdas8420 3 года назад

      Ok after 50 min

    • @krish7021
      @krish7021 3 года назад +1

      What is your qualifications

    • @ayushchampatiray7768
      @ayushchampatiray7768 3 года назад

      Would this work in case of a Ajax request where content type is just one string( application/x-www-form-urlencoded)

  • @falconfire8759
    @falconfire8759 3 года назад +103

    the quality of his video- 101%
    RUclips messing with his channel - 2000%
    result - max 10k viewers :/

  • @hemanthsankaramanchi5320
    @hemanthsankaramanchi5320 3 года назад +110

    Need more content like this.

    • @Iuffycs
      @Iuffycs 3 года назад +2

      @📌Pinnedby Tech Raj RUclips okay RUclips Bot

  • @bertrandfossung1216
    @bertrandfossung1216 3 года назад +11

    Raj I can't thank you enough for this beautiful and instructive content on SQL injection. I have learned a tone of new things. We need for content like this especially for bug bounty hunting. Thanks bro!!👍🏽🙏🏽

  • @avijitd22
    @avijitd22 3 года назад +23

    Need this types of videos from you

  • @harshitsinghGRIND
    @harshitsinghGRIND 3 года назад +16

    was waiting for a long time

    • @harshitsinghGRIND
      @harshitsinghGRIND 3 года назад +1

      @📌Pinnedby Tech Raj RUclips are you able to see who subscribed you?+ which browser do u love the most?

  • @fitnessbro8442
    @fitnessbro8442 3 года назад +13

    Expecting more content like this 🙏🙏🙏

  • @SinisteR2602
    @SinisteR2602 3 года назад +10

    We want more of these type of videos !
    You are doing a great job

  • @akshatdasondhi30
    @akshatdasondhi30 2 года назад +4

    Loved it, need more lessons like this thankyou ❤️🔥

  • @kurdmajid4874
    @kurdmajid4874 3 года назад +6

    Dude thanks a lot man ur vids are really informational

  • @kaustubhpaturi4801
    @kaustubhpaturi4801 3 года назад +19

    WE NEED MORE!!

  • @bruhhh-__-
    @bruhhh-__- 3 года назад

    There are many videos on SQL and I have learned but not the complete and it's interesting to learn from your favorite RUclipsr

  • @hrishikeshmahato4071
    @hrishikeshmahato4071 3 года назад +1

    Very informative as always ❤

  • @Abhinav-Bhat
    @Abhinav-Bhat 2 года назад +2

    Good one
    I would not see any Indian Course
    But today I am Proud of You
    Thank You Anna

  • @niveds9090
    @niveds9090 3 года назад +1

    Great content. Expecting more content like this.

  • @kspavankrishna
    @kspavankrishna 3 года назад +1

    GREAT VIDEO
    THANK You FOR MAKING IT

  • @vinayakpatil5214
    @vinayakpatil5214 Год назад

    Underated channel...the incredible way of exploitation explaination, hatsoff dude. keep growning bro.

  • @tarunvarma9828
    @tarunvarma9828 3 года назад +1

    We need more content like this more

  • @rustybolt_
    @rustybolt_ 2 года назад

    Frieking luv u man wonderfull explaination
    Liked and subbed!

  • @spy4045
    @spy4045 3 года назад

    Dude lot of thanks ❤️ good information

  • @gopi9368
    @gopi9368 Год назад +1

    Thanks!

  • @hacker-jd6cq
    @hacker-jd6cq 3 года назад +1

    Nice buddy thank you

  • @raahul2813
    @raahul2813 3 года назад +1

    Awesome bro

  • @cyberawm1158
    @cyberawm1158 3 года назад +4

    WoW! I even downloaded this

  • @DataInNutShell
    @DataInNutShell 2 года назад

    NICE VIDEO BHAI, liked it alot

  • @isha7359
    @isha7359 3 года назад +13

    I didn't knew that sql can be used for this i thought it was usless while learning it in my class😊
    But now😍

    • @NexPlayy
      @NexPlayy 6 месяцев назад

      🤣🤣🤣🤣

  • @GauravRai
    @GauravRai 3 года назад +11

    Most ignored thing in the world : This video's *DISCLAIMER* 😂😂

    • @techrajassistant7317
      @techrajassistant7317 3 года назад +1

      Thanks for your review...... For more information.... contact my recommended broker
      +1=4=2=3=8=0=1=8=4=0=6
      W/H/A/T/S/A/P/P""

  • @rastgo4432
    @rastgo4432 3 года назад +3

    Great tutorial bro , i hope u'll be making more of these cool content . 👏🏻

    • @priyansh5233
      @priyansh5233 2 года назад

      @📌Pinnedby Tech Raj RUclips Scammer.

  • @ALLISINONE
    @ALLISINONE 3 года назад

    Bro keep it up!

  • @HeyAsif
    @HeyAsif 3 года назад +12

    _Raj_ *Make some great courses please*

  • @akshayghoghari1821
    @akshayghoghari1821 3 года назад +1

    very Informative 👍👍

  • @fluffy280
    @fluffy280 2 месяца назад

    thank u for the video

  • @shivangsaraswat315
    @shivangsaraswat315 3 года назад

    You are doing great work please continue this serie..

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      ✓✓T•E•X•T•M•E✓✓
      ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓
      ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓
      A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @Knuddelfell
    @Knuddelfell 2 года назад +1

    love this

  • @SadTown99
    @SadTown99 2 года назад +1

    This channel covers a lot of content that is hard to find accurate information on these days… reminds me of the Wild West internet before everything got nerfed 🤓

  • @Siddharthtrading
    @Siddharthtrading 3 года назад +1

    Want more content like this🔥

  • @debashissatpathy5208
    @debashissatpathy5208 3 года назад +2

    First time I found a very usefull sponser.

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      ✓✓T•E•X•T•M•E✓✓
      ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓
      ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓
      A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @animeloverpakbj8229
    @animeloverpakbj8229 3 года назад +4

    I was just suffering a lot learning SQL injection
    Thanks a lot 🥺🥺❤️❤️😺

    • @techrajassistant7317
      @techrajassistant7317 3 года назад +1

      Thanks for your review...... For more information.... contact my recommended broker
      +1=4=2=3=8=0=1=8=4=0=6
      W/H/A/T/S/A/P/P""

  • @routetosuccess6716
    @routetosuccess6716 3 года назад

    Wow bro you are great 👌

  • @viresh222
    @viresh222 12 дней назад

    Bro this is elite 😮 🎉❤ love from Maharashtra

  • @khokon_m
    @khokon_m 3 года назад +1

    After giving a watch, I downloaded the video. Not sure if youtube removes this one too!

  • @harshog
    @harshog 3 года назад +1

    Love from you ♥️

  • @radai.
    @radai. 3 года назад +1

    Literally
    I love your English

    • @techrajassistant7317
      @techrajassistant7317 3 года назад

      Thanks for your review...... For more information.... contact my recommended broker
      +1=4=2=3=8=0=1=8=4=0=6
      W/H/A/T/S/A/P/P""

  • @shivamanish2280
    @shivamanish2280 3 года назад

    Which os should a starter should use windows or linex

  • @FrpKiller
    @FrpKiller 3 года назад

    Great demonstration

  • @s.kishorekumar8272
    @s.kishorekumar8272 3 года назад

    Love you bro

  • @yashu1089
    @yashu1089 3 года назад +1

    Good content deer

  • @aniketxcyber2415
    @aniketxcyber2415 3 года назад +1

    need more

  • @sathwikamin9147
    @sathwikamin9147 3 года назад

    Good one

  • @parrotsec2263
    @parrotsec2263 3 года назад

    Good Explanation

  • @tysonghaly4374
    @tysonghaly4374 3 года назад +1

    Going to the second half

  • @pratheekshetty.m5784
    @pratheekshetty.m5784 3 года назад +1

    We can also use google cloud docker right?

  • @KyrieBron
    @KyrieBron Год назад

    Brave man

  • @_AayushKumar
    @_AayushKumar 3 года назад +1

    Make a video on blind SQL injection

  • @jemilapinto8568
    @jemilapinto8568 3 года назад +2

    My friends Facebook id got hacked how we get that id

  • @EL-sc9on
    @EL-sc9on 2 года назад +1

    Instead logging in as the first user in the database, what do I enter to use ORDER BY RANDOM so I login as a random user

  • @shyampandey5546
    @shyampandey5546 3 года назад

    We need more content related. To ethical hacking raj big fan of yours

  • @gnanendraprasad1830
    @gnanendraprasad1830 3 года назад +1

    Hi bro there an issue for me how can i contact u

  • @bahai9706
    @bahai9706 3 года назад

    10,300th view
    Lots of love and support from Tripura (North-east)

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      ✓✓T•E•X•T•M•E✓✓
      ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓
      ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓
      A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @mamotechnology2368
    @mamotechnology2368 3 года назад +3

    thank you sir
    i appreciate the time that you spent to make this video and to teach us these stuffs
    i really respect you, hope you can teach us ethical hacking well but not on youtube cause , you know there're some rules in youtube that don't allow to share these things

  • @LOLIPOP119Jp
    @LOLIPOP119Jp 3 года назад +1

    Need more

  • @ArpanWasti
    @ArpanWasti 3 года назад +2

    Hello, Can you make video on something like Do's and Dont's for newbies who's have just started to learn? Likewise you said on well equipped environment and such stuffs like Is it safe using my personal emails on the Virtual Box or Dual booted linux distros where I practice injection, penetration tests and stuffs? And other common mistakes? Maybe hope I make some sense here. : )

  • @GoaBeach988
    @GoaBeach988 3 года назад

    Tq u

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      ✓✓T•E•X•T•M•E✓✓
      ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓
      ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓
      A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @ankitshaw1388
    @ankitshaw1388 3 года назад +2

    Man You are damn talented ❤️

    • @ankitshaw1388
      @ankitshaw1388 3 года назад

      @📌Pinnedby Tech Raj RUclips I Thought You are also from India

    • @ayushking_01
      @ayushking_01 3 года назад +1

      @@ankitshaw1388 ha ha its fake

  • @barathkumar588
    @barathkumar588 3 года назад +1

    Need more videos man...👍

  • @ALONE-RIDERN160
    @ALONE-RIDERN160 3 года назад

    Thanks bro 😁

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      W..H..A...T..S...A..P..P..><
      >>>>>>>>>>>>>>>>>>>
      +••1••5••1••6•• 3••9••9••1••9••1••1••

  • @pratismithgogoi4028
    @pratismithgogoi4028 3 года назад +1

    🔥🔥🔥🔥🔥more more more

  • @laxmikantsaraswat6319
    @laxmikantsaraswat6319 3 года назад

    Part 2🔥🔥🔥🔥🔥bhi aane de jaldi

  • @yashu1089
    @yashu1089 3 года назад +2

    lots of love from Russia

  • @yasirazam4976
    @yasirazam4976 3 года назад +2

    Bhi aik phone sa dosra phone hack kasy karna hai

  • @vasuparmar9963
    @vasuparmar9963 3 года назад

    Which is best for coding and hacking
    Windows Or Chromebook.??

  • @_AayushKumar
    @_AayushKumar 3 года назад +1

    What if login have email validation ? Which query to use for sqli

  • @xen.sky_8674
    @xen.sky_8674 3 года назад

    man i liek your mic can you add the link in desc?

  • @quewellschannel6999
    @quewellschannel6999 2 года назад

    SNYK same like NMAP?

  • @devarajanp.m2356
    @devarajanp.m2356 3 года назад +6

    Mallus ❤️

  • @pct0679
    @pct0679 3 года назад

    Pls Upload 1 video per week

  • @kartiksavaliya7192
    @kartiksavaliya7192 3 года назад

    Uplod more like this

  • @kshitijkumar9398
    @kshitijkumar9398 3 года назад

    Hi teja. Please make a video for a system that records attendance of students entered in meet,the time they remained. Please make

  • @coders_algoritmers1032
    @coders_algoritmers1032 5 месяцев назад

    Sqlmap showing me false positive and unexploitable point detected even vulnerability is available what i do please tell me

  • @MuhammadSheesAli
    @MuhammadSheesAli 3 года назад +2

    Tutorial will start at 5:01

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      ✓✓T•E•X•T•M•E✓✓
      ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓
      ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓
      A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @kutral99
    @kutral99 3 года назад

    Great raj, expecting contents like this.! 👍

  • @gouravunair9822
    @gouravunair9822 3 года назад +1

    Who needs his hacking course??

  • @justanuchiha3297
    @justanuchiha3297 3 года назад +1

    yee

  • @ranjannayak7930
    @ranjannayak7930 3 года назад +16

    Legends be like: *What is SQL* 😅😂

    • @Divaaakar
      @Divaaakar 3 года назад +3

      Structured query language

    • @ranjannayak7930
      @ranjannayak7930 3 года назад +1

      @@Divaaakar yeah 😂

    • @ranjannayak7930
      @ranjannayak7930 3 года назад +1

      @Md golam Mostofa 🤣

    • @b07x
      @b07x 3 года назад +2

      It's like a database managing language

    • @shreayankanjilal
      @shreayankanjilal 3 года назад

      @Md golam Mostofa It's easier than programing.

  • @falseloop
    @falseloop 3 года назад +5

    Great Tutorial Teja ;) Have a good day ♥

  • @Himanshu-Fy
    @Himanshu-Fy 3 года назад +1

    Sir make a video where we can mining in android via command/running python cudo/nanopool code use via in android make a video this goona be good 🔥

  • @TipsFishing343
    @TipsFishing343 3 года назад

    based decentralized content-sharing

  • @BeHappy-vr1ll
    @BeHappy-vr1ll 3 года назад +2

    More videos please 🥺🥺🥺

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      T•h•a•n•k•s f•o•r W•a•t•c•h•i•n•g. f•o•r m•o•r•e I•n•f•o o•r g•u•i•d•a•n•c•e
      W•H•A•T•S•A•P•P +•1•5•1•6•3•9•9•1•9•1•1

  • @Trikoo
    @Trikoo 3 года назад +5

    Extremely waiting for u bro ❤️❤️❤️❤️❤️❤️❤️❤️❤️
    Imagine getting pinned by *TECH RAJ*

    • @avijitd22
      @avijitd22 3 года назад +2

      Reality : Get Reply from Scammers 🤣🤣. Named pinned by Tech Raj

    • @Lokendrakushwah12
      @Lokendrakushwah12 3 года назад +1

      Your comment is pinned by Tech Raj

    • @Trikoo
      @Trikoo 3 года назад +1

      @@Lokendrakushwah12 no bro

    • @avijitd22
      @avijitd22 3 года назад +1

      @@Trikoo he is joking buddy 😂😂

    • @Trikoo
      @Trikoo 3 года назад +1

      @@avijitd22 ooooo😂😂😂😂😂😂😂😂😂😂

  • @adarshranjan2935
    @adarshranjan2935 2 года назад

    Please make a video on how to extract drm key 🔑 from drm url

  • @chauhanravi5664
    @chauhanravi5664 3 года назад +4

    👍👍👍

  • @ekalabya_syst9299
    @ekalabya_syst9299 3 года назад +1

    1 05 " so bhaiya "🤣🤣

  • @IM5NFF
    @IM5NFF 3 года назад +1

    Bro can u plzzz say ur pc specs plzz bro

  • @adil.m
    @adil.m 3 года назад

    Plzzz make more brooooo pzzzzzzz🙏🙏🙏🙏🙏🙏🙏🙏

  • @sloughpacman
    @sloughpacman 2 года назад

    Good video, didn't like the Snyk promo at the end.

  • @pratheekshetty.m5784
    @pratheekshetty.m5784 3 года назад +1

    Sir please make a video about phoneinfoga

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      T•h•a•n•k•s f•o•r W•a•t•c•h•i•n•g. f•o•r m•o•r•e I•n•f•o o•r g•u•i•d•a•n•c•e
      W•H•A•T•S•A•P•P +•1•5•1•6•3•9•9•1•9•1•1

  • @ajay316
    @ajay316 3 года назад

    Mining videos please

  • @xundansingh5618
    @xundansingh5618 3 года назад

    We have better way to do ! But i appreciate because you focus on basics

    • @adminbyseregasoleniyminer4490
      @adminbyseregasoleniyminer4490 3 года назад

      ✓✓T•E•X•T•M•E✓✓
      ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓
      ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓
      A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @kishanraokumbham5048
    @kishanraokumbham5048 3 года назад +1

    Broo i want resources for learning web security can you plzz help me pointing in right direction I'm confused totally what n where to study and practice plzzxx

    • @techrajassistant7317
      @techrajassistant7317 3 года назад

      Thanks for your review...... For more information.... contact my recommended broker
      +1=4=2=3=8=0=1=8=4=0=6
      W/H/A/T/S/A/P/P""

  • @ravindran_1
    @ravindran_1 3 года назад +1

    Sir i wanna learn how to hack color prediction games I need ur help
    Plz sir help...