Real World Hacking Demo with OTW

Поделиться
HTML-код
  • Опубликовано: 28 сен 2024

Комментарии • 374

  • @davidbombal
    @davidbombal  Год назад +72

    This is a real world demonstration of the SQL Injection attack used in the recent MOVEit hack. This is real world - not just a simple SQL attack.
    Big thank you to Juniper Networks for supporting the community and making this training free (and sponsoring my channel). Go to juniper.net/davidbombal to get lots of training and also learn how to get certified for $50 (Associate Level). Use this voucher code to register for your courses: DAVIDBOMBAL
    If you have issues with the Juniper registration, please use these links that they gave me:
    For Login assistance link userregistration.juniper.net/loginassistance
    Customer Support link- support.juniper.net/support/requesting-support/
    // Mr Robot Playlist //
    ruclips.net/p/PLhfrWIlLOoKNYR8uvEXSAzDfKGAPIDB8q
    // Proof of Concept //
    Horizon3: www.horizon3.ai/moveit-transfer-cve-2023-34362-deep-dive-and-indicators-of-compromise/
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: twitter.com/davidbombal
    Instagram: instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    RUclips: ruclips.net/user/davidbombal
    // Occupy The Web social //
    Twitter: twitter.com/three_cube
    // OTW Discount //
    Use the code BOMBAL to get a 20% discount off anything from OTW's website: davidbombal.wiki/otw
    // Occupy The Web books //
    Linux Basics for Hackers: amzn.to/3JlAQXe
    Getting Started Becoming a Master Hacker: amzn.to/3qCQbvh
    Top Hacking Books you need to read: ruclips.net/video/trPJaCGBbKU/видео.html
    // Other books //
    The Linux Command Line: amzn.to/3ihGP3j
    How Linux Works: amzn.to/3qeCHoY
    The Car Hacker’s Handbook by Craig Smith: amzn.to/3pBESSM
    Hacking Connected Cars by Alissa Knight: amzn.to/3dDUZN8
    // MY STUFF //
    www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
    // MENU //
    00:00 - Coming Up
    00:55 - Juniper Free Training (Sponsored segment)
    01:51 - OccupyTheWeb books and new books
    03:57 - The MOVEit breach explained
    05:20 - Clop website // Companies affected
    08:52 - The two different vulnerabilities
    10:26 - The truth about SQL Injection
    12:21 - Using Shodan
    14:05 - Proof of concept of the exploit
    16:18 - SQL Injection example
    20:35 - MOVEit hack analysis / How it was done
    28:57 - CVE-2023-35708 SQL Injection vulnerability explained
    30:36 - What is Taiwan Semi-Conductor (TSMC) and why they got hacked
    31:01 - SQL Injection hack in the real world
    32:45 - OccupyTheWeb online classes
    33:46 - Union statement // Stacking queries demo
    37:02 - Upcoming OccupyTheWeb courses and classes
    39:50 - Conclusion
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.

    • @lrplinking1771
      @lrplinking1771 Год назад

      Sick

    • @cw9352
      @cw9352 Год назад +1

      Juniper network training not working. their link to register is down currently, keeps taking me in circles.

    • @s.m.1354
      @s.m.1354 Год назад

      PEGASUS SPYWARE:
      Pegasus has the ability to access devices, without victims pressing a link, is what they learned us so far. But that is a lie, it is way more Intelligent than that.
      The Virus is hidden in Memes and Thumbnails, it’s spread across the World every time after devices Update, using Social Media, and Unaware Victims Executing video’s, Thumbnails, images etc.

    • @waystomakelifebetter
      @waystomakelifebetter Год назад +1

      Ty for everything you do

    • @funkymonk2254
      @funkymonk2254 Год назад +1

      ThankYou for the new video Mr Bombal.

  • @_JohnHammond
    @_JohnHammond Год назад +26

    Very cool to see the MOVEit coverage here -- and especially thank you for the Huntress shoutout! :)

    • @davidbombal
      @davidbombal  Год назад +10

      Great to see you here John!! You and the team at Huntress are amazing! Got to get you back here :)

    • @SajidQureshi__
      @SajidQureshi__ Год назад +1

      @@davidbombal hey can you guys make a full website deface video plz its very common people search for but they dint get much info on that i hope OTW may do it or john

  • @mason35715
    @mason35715 Год назад +57

    You two never fail to disappoint. Amazing as always OTW and David. Bravo

    • @davidbombal
      @davidbombal  Год назад +7

      Thank you very much!

    • @pgprog
      @pgprog Год назад

      UNION you also have to have the same data type : varchar,number,DateTime etc

    • @mr.bouncealot9047
      @mr.bouncealot9047 4 месяца назад

      Never fail to disappoint.. 😅

  • @TinkerTech
    @TinkerTech Год назад +46

    The knowledge flows out of him so casually and easy to understand.
    Its typically a skill you find in someone that's been doing "It" most of their life.
    He teaches as easily as someone else might tie their shoes.

    • @davidbombal
      @davidbombal  Год назад +18

      Agreed! "If you can't explain it simply, you don't understand it well enough." Albert Einstein

  • @GymRatJunkie
    @GymRatJunkie Месяц назад

    This channel is an absolute gem for the IT community! Thank you for bringing consistently great content, David!

  • @taraurbanovitch2686
    @taraurbanovitch2686 Год назад +3

    I'm a SQL developer who is trying to transition into Cybersecurity (just passed CompTIA Security +), and I REALLY enjoyed this! Thank you

  • @yashbandhiwal
    @yashbandhiwal 10 месяцев назад +2

    Occupytheweb your voice is life. So calming. ^_^

  • @beautifullybrilliant7542
    @beautifullybrilliant7542 Год назад +1

    1:2 7 THANK YOU SO MUCH DAVID for going the extra mile for us. you subscribers!!!! Just yesterday I had to turn down getting CEH CERT as the entire only 8 - 12 week program plus extra for the exam. There was simply NO way I could afford the $2800 USD+ fee; especially bung in Canada. Thant's like $3600!!!! Simply love your channel and your constant commitment to others :)

  • @miyu545
    @miyu545 Год назад +1

    That's why stored procedures are the best option to avoid any issues with what the DB does or what data is involved.

  • @marinob7433
    @marinob7433 Год назад +84

    OTW=respect.

  • @godadawgashaw4965
    @godadawgashaw4965 Год назад +2

    It is very intersing concept that show how hacker use sql injection in real world with more advanced techniques to atteck their target ,this teach alot david thanks alot as always

    • @davidbombal
      @davidbombal  Год назад +1

      You're welcome! I think it's great to see a current, real version of this, and then to learn the basics if you don't know yet :)

  • @SkeltherBot
    @SkeltherBot Год назад

    Seeing OTW, instant like and watch. Best content on YT, and best content on your channel! Waiting for more, great stuff.🤞

  • @ivanomaras2776
    @ivanomaras2776 Год назад +1

    "You can't be a hacker if you don't know programming... If I read source code and understand it, it's because I'm capable of writing it."

  • @Lash-LhineDisten
    @Lash-LhineDisten 10 месяцев назад +1

    Great content as always. Would love to see more content with OTW, you guys should make that video you talked about on how to reprogram usb drives into rubber duckies.

  • @botsk33
    @botsk33 Год назад +1

    Another amazing episode, cheers Gentlemen! These should be the MOST EXPENSIVE punctuation marks of all time for each company during the SQL attack. xD In fact forgetting about "oldschool" attack techniques is a common mistake many companies / services make all the time (also from my experience). I mean - Aerosmith was founded in 1970 and it's still a nice band, right? :)

  • @alsadekalkhayer7007
    @alsadekalkhayer7007 Год назад +5

    David, we enjoy OTW, and you are the reason we know him. So, thank both of you

  • @andrewrobison581
    @andrewrobison581 Год назад +1

    awesome video, i love all the information and links you provide. you guys are nailing it!! keep it up

  • @DeepakSharma-kx6nf
    @DeepakSharma-kx6nf 6 месяцев назад

    I love OTW❤❤❤❤❤.... and also DAVID BOMBAL who represent this type of man on the viewers....

  • @AusieGamer834
    @AusieGamer834 Год назад +4

    It’s hard to believe someone out there who is more skilled than otw. Impressive work. Thanks David and otw for bringing this to our attention. You both are the best.

  • @Joe-f1z3h
    @Joe-f1z3h 4 месяца назад

    man i love ur content. i follow u on spotify as well. more otw and sparc flow pls and ty david. JUST GREAT CONTENT!

  • @ebooooo1213
    @ebooooo1213 Год назад +4

    Im a student of OTW and his classes are top notch in every aspect! Thanks David for the interview, RESPECT ❤️

    • @sdwsom4287
      @sdwsom4287 Год назад +1

      So do u really recommend me to buy a subscription to his classes?, since it will be very expensive to me.

    • @ebooooo1213
      @ebooooo1213 Год назад

      @@sdwsom4287 if you want, try his classes in the gold membership which is monthly then upgrade your membership

    • @sdwsom4287
      @sdwsom4287 Год назад

      @@ebooooo1213 OK thanks mate.

    • @ebooooo1213
      @ebooooo1213 Год назад

      @@oppenheimer11 they have different levels. You can get the starter bundle get some knowledge then join classes

  • @deviantdapperdude8983
    @deviantdapperdude8983 Год назад

    Looks like you’re in Utah David, next time you’re in town reach out, I’ll take you out rallying some side by sides, show you some great hiking and camping spots and teach you some survival stuff!!! Great video!!

  • @caseyburhoe7449
    @caseyburhoe7449 Год назад +2

    The organization I work for was affected by that security breach, it was scary to think about but as someone in the IT world, it was interesting to learn about it.

  • @landrover827
    @landrover827 Год назад +1

    Always happy to have OTW and you posting videos on here together🎉🎉

    • @davidbombal
      @davidbombal  Год назад +2

      Thank you. Lots more to come!

    • @landrover827
      @landrover827 Год назад

      @@davidbombal can we get a Neal + OTW round table discussion?! 🫣🤩

  • @potencypal7596
    @potencypal7596 Год назад

    It's always amazing learning you and much more when master OTW is in class. Thanks to you both.
    I really wish you could do a tutorial video on Juniper registration, somethings ain't really clear to me. Thanks for the prime lectures and keep adding flavors to your teachings ✌️

  • @sunchimoonchi
    @sunchimoonchi 11 месяцев назад

    The ... " we have a chance moment" just awesome.

  • @TheOriginalJohnDoe
    @TheOriginalJohnDoe Год назад +1

    What a guy you are, David. In the middle of the mountains taking a moment to record something for your sponsor 😂

  • @viktoreidrien7110
    @viktoreidrien7110 Год назад +1

    such a good good video, the knowledge alone is overwhelming and at the same time very understandable, love your channel and love even more OTW, thank you.

  • @relaxaredormir9694
    @relaxaredormir9694 Год назад

    Thank you David and OTW, to talk and share you knowledge, all the content you do is very valuable. I learn so much with you guys. Ohh!!! John pass for here too. 😂😂😂 Another great person with nice contents. Thank you guys.

  • @pjteros
    @pjteros Год назад

    very cool as always ;). Good story, cold beer and OTW!

  • @althebeastly
    @althebeastly Год назад +1

    love the OTW episodes...would love a more in depth episode on ss7 and 2fa also if possible

  • @rassannimaronie4664
    @rassannimaronie4664 Год назад

    Great video / content again David, wasn't sold on the hacking videos at the beginning 😅 but I have definitely being enjoying the content. Very informative

  • @gregoriozucchi45
    @gregoriozucchi45 Год назад +2

    Great video! Loved it! So clear! Question for you and OTW: wouldn’t any of these big companies have a SIEM blocking exfiltration in big sizes? I recall Sentinel going off alarms and bella when users moved/deleted large volumes of data? Maybe a dumb question…but any answer would be appreciated thanks!

  • @Just_A_Tech.._
    @Just_A_Tech.._ Год назад +1

    Many thanks to you David and OTW for the great job you're doing. Maximum respect.🙌🙌

  • @mytechnotalent
    @mytechnotalent Год назад +1

    This sure is real. Again LOVE seeing you covering these topics David and GREAT to see you OTW!

    • @davidbombal
      @davidbombal  Год назад

      Thank you. So nice having OTW share his knowledge and experience with all of us 😀

  • @ray73864
    @ray73864 Год назад

    Makes me glad we don't use that particular software from Progress :) Also makes me glad that the software we do use of theirs (their DB software) barely even supports SQL89, and requires you to have the SQL broker enabled for it to even work.

  • @nsekaanatole7750
    @nsekaanatole7750 Год назад

    Thanks David and OTW.
    Very knowledge filled.

  • @Abdullah-wh6ge
    @Abdullah-wh6ge Год назад

    Great 👍 thanks @David as usual learnt a lot

  • @cajunphilippine
    @cajunphilippine Год назад

    Excellent content my friend David and OTW.

  • @JohnMandersonBM
    @JohnMandersonBM 11 месяцев назад

    That was brililant info. I must have missed when this came out.

  • @a.iananda1215
    @a.iananda1215 Год назад +3

    hi sir can you please make a video on pivoting devices and discuss of it with master occupy the web!

    • @davidbombal
      @davidbombal  Год назад +1

      Great suggestion

    • @a.iananda1215
      @a.iananda1215 Год назад

      @@davidbombal thank you sir !! i am looking forward to it

  • @mmet0diev
    @mmet0diev Год назад +2

    It's not about cyber sec only for you to be exposed to some simple sql injection techniques and how it works in the back, even for us in Software Engineering/Comp Science, one of my lecturers in the web app networking module discussed with us about sql injection, cross site scripting, and other sorts of old school hacking techniques, honestly, I think that every single person involved into IT needs to have at least a basic grasp/knowledge of these technoiques and their basics, or at least know what they are about, maybe in the near future everybody will need to know this, which I'm not really a fan of but, the world is moving forward, and we all need to adapt to it.

  • @sultansheikh2797
    @sultansheikh2797 Год назад +2

    Love you sir from india😊

    • @davidbombal
      @davidbombal  Год назад +1

      Thank you! I appreciate your support!

  • @slumb3rx
    @slumb3rx Год назад

    Thank you, David, for everything

  • @derelictmanchester8745
    @derelictmanchester8745 Год назад

    Brilliant video David and OTW...🌟

  • @Dr.DomAPI
    @Dr.DomAPI Год назад

    Thanks David I really need that video 👍❤️

    • @davidbombal
      @davidbombal  Год назад

      You're welcome! I hope you enjoyed the video 😀

  • @Michaelno
    @Michaelno Год назад

    I work in a SOC. I'm going to buy this guy's books for sure.

  • @Scorpy2303
    @Scorpy2303 Год назад

    Listen David your channel is outstanding!!! No two ways about it. Your video's with otw are just the best. The level of detail and information in these video's are so easy to follow it's unreal. As a 33 year old man who worked in construction his whole life, I cought covid last year and it messed me up so much I had to give up my job, literally in a dark place trying to figure out what the F im gonna do now I found your first vid with otw and instantly became hooked on learning everything I can about hacking (pretty sure my partner is sick of me burning the ear off her on stuff I learn 😅) . Half way through linux basics for hackers and just received his second book!!! So far amazing!!! When I build up the funds I'll become a subscriber hopefully! David keep up the amazing content I appreciate your hard work!!! Your the man!!!

  • @yelov8504
    @yelov8504 Год назад

    There is no doubt that you will rise fast at the apex of your career MetaspyClub . Because you are a very intelligent, smart, hard worker and your work ethic par excellence. Keep going People like you take the IM out of IMpossible by becoming PRO at tackling PROblems. You Rock!.

  • @galebibrahem535
    @galebibrahem535 Год назад +4

    Mr. David, you are like Cristiano Ronaldo in Cyber, but who is Messi? , he is occupy 🤔🤔
    occupy
    How are you?
    I missed you man 😊
    Big thanks Mr David ❤

    • @davidbombal
      @davidbombal  Год назад +2

      Thank you! But, you are too kind 😀

  • @ACID1337xx
    @ACID1337xx Год назад

    Very nice content sir! Thank you very much

    • @davidbombal
      @davidbombal  Год назад +1

      Thank you! Glad you enjoyed the video :)

  • @Blackmanfreeman
    @Blackmanfreeman Год назад

    This duo you are amazing. Thanks for those knowledge

  • @millertime6
    @millertime6 Год назад

    Ooh this hack was a work of art. Good analysis!

  • @MorrWorm8
    @MorrWorm8 Год назад

    OTW!! Let’s gooo!

  • @friendlynightmeres
    @friendlynightmeres Год назад

    Thank you Juniper, thank you David for this and to Occupie the Web the G.O.A.T. for your time a biblical, Dankie...A DANKO 😂

  • @VulcanOnWheels
    @VulcanOnWheels 3 месяца назад

    26:31 I was hoping we would only have to contend with this ridiculous scene once.

  • @PauliusBieliauskas
    @PauliusBieliauskas Год назад

    Every time I see new vid I’m happy that i pushed the subscribe button

  • @syedsheeban8838
    @syedsheeban8838 Год назад

    Bombal Sir. I am very Sorry. I ddos'ed your site. I thought it would be difficult. But it was gone on the first try. But now ddos is not working. The reason is you are a very Good hacker. You fixed the site and now it is not getting affected.

  • @barthsheyin206
    @barthsheyin206 Год назад +1

    David I really love your videos.
    Could you please give me the e Juniper Elevators community learning 'Elevate Auth Code'?

  • @icecoldnoob6719
    @icecoldnoob6719 Год назад

    that intro 🤣
    Any Devops content or talking about demanding skills soon?

    • @davidbombal
      @davidbombal  Год назад +1

      Thank you! I'm working on it 😀

  • @alfredopiscante1292
    @alfredopiscante1292 18 дней назад

    It's good to educate the people

  • @0027speedy
    @0027speedy Год назад

    Thanks David and OTW

  • @yughiole7088
    @yughiole7088 10 месяцев назад

    Những Video có OTW thật sự rất hay!!

  • @prolinuxtutorials
    @prolinuxtutorials Год назад +1

    Your videos are super cool so even I make videos like you do! Cool videos you make...........

  • @S1ck0fant
    @S1ck0fant Год назад

    Will Linux Basics for Hackers get updated? I just recently bought it and got to chapter 3 but some of the stuff requires further research and different tools or routes to get to. I understand this is probably just a normal case of Welcome to Tech! Im just wondering if there are planned updates or expansions on the content.

  • @FrankMenoken
    @FrankMenoken 2 месяца назад +1

    I do not know how to turn a PC on so how do I learn how to code

  • @BunnyTamang-v8i
    @BunnyTamang-v8i Год назад +1

    David Bombal does that book have the pdf so the I can read because in my country amozon is not muxh aviable plz replay to this comment???? sir

  • @RoomTwentyNine
    @RoomTwentyNine Год назад

    I really enjoyed contents with OTW

  • @vincenzopetrucci4416
    @vincenzopetrucci4416 Год назад

    Excellent explications , good for kids

  • @cybersecuritydeclassified4793
    @cybersecuritydeclassified4793 Год назад

    Another outstanding episode with OTW. Guy is right up my alley.

  • @aechapark4299
    @aechapark4299 Год назад

    SQL injection can be still use in bug bounty hunting? How about the impact?

  • @guneyaliunal9981
    @guneyaliunal9981 Год назад

    thanks mate really useful :)

  • @tamly6852
    @tamly6852 Год назад

    Hi David, why my vmware workstation just has Ethernet connection, and my wifi adapter usb does not work in kali linux

  • @ab99degaming30
    @ab99degaming30 Год назад +1

    mr david . you are so good . please can you teach us how we can generate GPT with use only my user data and no wifi connect .please that will be good for all flowers

  • @ianm00n
    @ianm00n Год назад

    Do they strip or filter only once? lets say for example, i insert two commas and only one gets deleted.

  • @funkymonk2254
    @funkymonk2254 Год назад

    OTW OTW!!!

  • @andrewwood1502
    @andrewwood1502 Год назад

    I find one part confusing, how does everyone have access to their internal code? Is MoveIt open source?
    Am I understanding correct that OTW thinks they specifically attempted random SQL injection on the databases for years to stumble upon the vulnerability or did they likely analyze the code first then look further?

  • @xkeyscore1120
    @xkeyscore1120 Год назад

    Brilliant video

  • @MOGE_
    @MOGE_ Год назад

    If they don't have access to the code, then how do they know the table names, collumn names and other things as such?

  • @full_automation
    @full_automation Год назад

    I just love this man

  • @bronxandbrenx
    @bronxandbrenx Год назад

    So brilliant :)

  • @rosemariedecena7981
    @rosemariedecena7981 Год назад

    QTW your amazing❤

  • @osmansblog2645
    @osmansblog2645 6 месяцев назад

    Thank you sir. I am a Bangladeshi fan of Occupythe web... But my first Language is not English... How can I read the book getting started becoming a master hacker in Bengali language. Or has anyone translated it in Bengali language? It would have been if Ori also got a Bengali book.

  • @Abduselam.m
    @Abduselam.m Год назад

    Really interesting topic

    • @davidbombal
      @davidbombal  Год назад

      Glad to hear that you are enjoying the video :)

    • @Abduselam.m
      @Abduselam.m Год назад

      I’m from Ethiopia and I don’t have any money to pay to learn
      I’m currently preparing for ccna exam for next month and I need some resources to study

  • @00Jimmy00
    @00Jimmy00 Год назад

    please cover SDR, sub-gig and etc

  • @Engamerff
    @Engamerff Год назад +1

    Sir big fan

  • @miftahx_fan3297
    @miftahx_fan3297 Год назад

    Saying “thank you” is not enough to show my gratitude to you MetaspyClub . An honor to work under your guidance. Thank you for everything and mostly important the phone tracking was so satisfying

  • @guilherme5094
    @guilherme5094 Год назад

    Really nice👍👍!

  • @malharpatel7723
    @malharpatel7723 Год назад

    Thanks for training info @David bombal

  • @X-razcal-X
    @X-razcal-X 11 месяцев назад

    When comes up the next vid with you and otw? I bought his book in hope he has an income to take time for content with you 😂🎉

  • @heitormbonfim
    @heitormbonfim Год назад

    I've tried to register an account in Jupiter, but it's a pain in the ass (feedback for them) as cofusing as a blind man in the middle of a shooting

  • @sunchimoonchi
    @sunchimoonchi 11 месяцев назад

    Ty ser ❤

  • @MangolikRoy
    @MangolikRoy Год назад

    I don't even realise how 40mints past away much interesting topic fore sure

  • @gUm_bY745
    @gUm_bY745 Год назад

    Why can't I select All notifications?

  • @mytechnotalent
    @mytechnotalent Год назад

    I also send a few people a link to your training. David, as always, the best! How do you get it all done!

    • @davidbombal
      @davidbombal  Год назад

      Thank you! That training that I mentioned isn't content that I created, but made by Juniper 😀

    • @mytechnotalent
      @mytechnotalent Год назад

      @@davidbombal yes sorry I meant your link but nonetheless you are helping provide critical skills to so many who just don't have a great deal of resources.

    • @davidbombal
      @davidbombal  Год назад

      @@mytechnotalent Thank you 😀

    • @mytechnotalent
      @mytechnotalent Год назад

      @@davidbombal pleasure as always David!

  • @carsonjamesiv2512
    @carsonjamesiv2512 Год назад

    GOOD INT3L.👍💯

  • @bachirbenmouloud2023
    @bachirbenmouloud2023 Год назад

    Hi Mr David, please make a video about WormGPT

  • @anthonym.4356
    @anthonym.4356 Год назад

    thx

  • @manavrupani2460
    @manavrupani2460 Год назад

    I have a question how do these attackers know the table names and the fields in the table, is it by the fuzzing process mentioned by OTW, is it by studying source code through inspection or something else ?

    • @MOGE_
      @MOGE_ Год назад

      i literally have the same quesiton. i reckon they don't have access to the source code as that would make it easy to exploit.

  • @stpaquet
    @stpaquet Год назад

    Could a row level encryption have prevented the attacker from taking usable data out of the database?