Advanced SQL Injection Tutorial

Поделиться
HTML-код
  • Опубликовано: 23 ноя 2024
  • НаукаНаука

Комментарии • 217

  • @presenzemisteriose
    @presenzemisteriose 3 года назад +36

    Hi, I bought the course, can I write to you privately for any questions? thanks you are the best

    • @LoiLiangYang
      @LoiLiangYang  3 года назад +18

      Yes. Feel free to post your questions in Udemy and our team will get right back to you! If you're a RUclips member of this channel, likewise too!

    • @presenzemisteriose
      @presenzemisteriose 3 года назад +6

      @@LoiLiangYang Thank you very much, I also sent you a message on udemy, I'm watching videos on payload on Android but I had problems in practice I write to you thanks again, and I must say you teach well good ☺️

    • @presenzemisteriose
      @presenzemisteriose 3 года назад +1

      how do i port forward for with smartphone connection

    • @rohimpiana711
      @rohimpiana711 3 года назад +2

      How can I become a youtube member ?

    • @trickshot8653
      @trickshot8653 3 года назад

      @@LoiLiangYang could you please make a video for hacking database using sql injection . All techniques possible

  • @LoiLiangYang
    @LoiLiangYang  3 года назад +15

    Additionally, you look for vulnerabilities in the input fields by throwing in payloads to get error. This is important because once you discover the vulnerability, the advanced segment of using UNION to pull out more data comes in to play.

    • @swarnabhargavi5680
      @swarnabhargavi5680 2 года назад

      Plz do SQL injection video of Login Page having Captcha. All videos on internet shows only on Login page having Username and Password

  • @yunus-gedik
    @yunus-gedik 3 года назад +5

    Loi is the best security instructor on RUclips .
    Thanks from 🇨🇵

  • @shubhankarparanjape7693
    @shubhankarparanjape7693 3 года назад +24

    I can’t express how underrated your channel is considering how amazing & valuable content you are providing. Keep it up man, major hats off to you! Lots of love from India 🇮🇳

  • @chillydoog
    @chillydoog 3 года назад +4

    Your voice is so soothing and smooth. Handsome, smart, effective.

  • @thundermc4480
    @thundermc4480 3 года назад +1

    You are a life changer for me. I always wanted to do ethical hacking. And now i work on a univeruity

  • @technologymakeeasy
    @technologymakeeasy 3 года назад

    Thanks my teacher, i have hijack a website using your way. And now i have 1000% full access -

  • @_Thomas_Shelby_
    @_Thomas_Shelby_ 3 года назад

    In pandemic time ur spending ur precious time to teach 4r us sir,by cing ur cls.. in udemy we have learnt Sir tq sir.

  • @arshadakl
    @arshadakl 3 года назад +13

    make a video about SQL injection filter bypassing

  • @X-secular
    @X-secular 3 года назад +40

    Love ❤️ from India 🇮🇳

    • @john_vinith
      @john_vinith 3 года назад +2

      🇮🇳

    • @b07x
      @b07x 3 года назад +4

      Love ❤️ from Turkey 🇹🇷

    • @secretmystery8305
      @secretmystery8305 3 года назад +3

      1st & 2nd cmt from BD but pinned cmt fro. in. Really this is heart Broken think.😔🙄😒🤔

    • @X-secular
      @X-secular 3 года назад +2

      @@secretmystery8305 don't worry bro.... Good luck for next time....

    • @secretmystery8305
      @secretmystery8305 3 года назад +1

      @@X-secular Thank You So Much. :)

  • @Moderator.
    @Moderator. 3 года назад +7

    But what about the Salt into Hashing.. Almost everyone does it now... A salted hash can't be reversed.

  • @aiziz1658
    @aiziz1658 3 года назад +3

    this is great man, exactly same as what i leran from school

  • @sharmaabhijit5831
    @sharmaabhijit5831 3 года назад +1

    Lot of Respect to your Work Sir.
    Like a consistent student who regularly watches your video but I have a query from where u get sql payload can u make a video on that how to find or check payload available

  • @iuseyahoo
    @iuseyahoo 3 года назад

    Loi I learn more from you in a 5 minute video rather than someone else’s 15 min video

  • @Alain9-1
    @Alain9-1 3 года назад +2

    Underrated channel

  • @ewaat
    @ewaat 3 года назад +2

    I just can't wait for other videos, much love from Kenya

  • @gostxost
    @gostxost 4 месяца назад

    Mr Loi, you used the SQL injection attack with a completely different method. I thought you would run code like or '1=1# or or 8888=8888--. Then you will find the tables and columns on the site. I thought you would capture it.
    I can use sqlmap, but I cannot do it manually. Because I didn't fully understand how to do it.

  • @kodjovinicolasanatoh4521
    @kodjovinicolasanatoh4521 3 года назад +2

    Please I need a video on how to access friends contact list by Link. Or by generating a payload.
    Thanks

  • @secretmystery8305
    @secretmystery8305 3 года назад +4

    Love From Bangladesh :)

  • @Nihillius
    @Nihillius 3 года назад +1

    you are The best by the way i am You Fan i saw every videos

  • @japhetmnyeta1076
    @japhetmnyeta1076 2 месяца назад

    Your good brother,your tutorials are understandable

  • @marcush3ll673
    @marcush3ll673 3 года назад +2

    Love from INDIA ❤️

  • @nazarshved7504
    @nazarshved7504 3 года назад +1

    How would you know the exact name of a table and it's columns?

  • @varunfoodvlog9215
    @varunfoodvlog9215 3 года назад

    hey u are a osm osm hacker wow i am fast time see your channel from india and u grow more

  • @gamekanstudios
    @gamekanstudios 3 года назад +2

    Thanks mr loi for teaching me

  • @freelancersharif2051
    @freelancersharif2051 3 года назад

    wow, wonderful, we want more tutorials. thank you so much for sharing this valuable hacking method. take love from Bangladesh

  • @abczwq8364
    @abczwq8364 Год назад

    and how did you discovered those were valid fields on the user table? ..how did you discovered the table name? how did you discovered the type of database ? ... if this is an advance tutorial you should explain how did you came up with the payloads , not just to do a copy paste

  • @john_vinith
    @john_vinith 3 года назад

    Good channels are mostly under rated... Very useful content.... yesterday i was looking for this... 🖤🖤🖤

  • @isakadzemusicc
    @isakadzemusicc 2 года назад

    how to use this teqnique when there is no searchbar and there is only login and password fill forms?

  • @tassiblezilundu7602
    @tassiblezilundu7602 3 года назад

    Let me confess that you're the best Loo Liang.... I want to make just one request.... make a video that would cover how to locate a phone number currently working and combined with one which is not currently working thanks

  • @NicatZadeh
    @NicatZadeh Год назад

    Hello, some cyber security expert told me that real site is not actually attacked in this way. Do you think this is true? Should I try your suggested method if I want to attack any site? Please reply. I want to ask one more thing. What is a sql map? What is the difference between sql map and this specified method? How can we do this?

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 3 года назад

    Wow i was inpressed SQL Injection should not be as difficult its all on what happens on the server.

  • @devanshkanda9618
    @devanshkanda9618 3 года назад +1

    Thank you sir ❤️ love from india ❤️❤️

  • @smahidhar516
    @smahidhar516 3 года назад +1

    Bro where i can learn ethical hacking from basics to advance

  • @jackpersonal9657
    @jackpersonal9657 3 года назад +1

    Is this advanced? Can you make an even more advanced one where you talk about information_schema etc and find the tables manually without being given the stuff like in this video, or bomb shells or writing or reading mitigation

  • @ChandupaHerath
    @ChandupaHerath Год назад

    I think for hashing MD5 algorithm is not the industry standard.

  • @nosignal5735
    @nosignal5735 3 года назад +1

    If I may know, does cyber security pay well? Average per year? And which one makes more money, cyber sec or game development company? I'm interested in both fields but I don't know which one to choose....

    • @mrintel10
      @mrintel10 2 года назад

      I'd say cyber security but with game development it varies on your position as with cyber security

  • @st1llbleed1ng
    @st1llbleed1ng Год назад

    Man your first union select query, was it fluke or actually there were 9 columns in users table? Also can you explain why you used /**/?
    Finally all the columns except the last one in the users table were string type?

  • @rafin5651
    @rafin5651 3 года назад +1

    Love from Bangladesh 🇧🇩❤️😊

    • @mukto2004
      @mukto2004 3 года назад +1

      hacker from bd i see

    • @b07x
      @b07x 3 года назад

      @@mukto2004 🇹🇷🇧🇩🇩🇿🇮🇳🇵🇰🇨🇳🇷🇺🇺🇲🇬🇧 Most of the hackers are from these countries.

    • @mukto2004
      @mukto2004 3 года назад

      @@b07x pak ? How ?

  • @arshadakl
    @arshadakl 3 года назад +1

    How can monitor mobile traffic using wireshark

  • @a-71ameymuke84
    @a-71ameymuke84 3 года назад

    You are great teacher sir I have learned many things from you Much love and support to you❤❤💯

  • @oaychicolofi4845
    @oaychicolofi4845 2 года назад

    how can i come up with that union select, kinda weird

  • @sahilrajput3063
    @sahilrajput3063 3 года назад +1

    make a video on API

  • @Zero5309
    @Zero5309 3 года назад +6

    Really well explained! What I would like to have are more realistic attacks. I mean are there actually still up to date webapps with that kind of vulnerabilities? What would a SQL injection look like in realistic scenario? Still a great video :)

    • @roniwinchester8351
      @roniwinchester8351 3 года назад

      understanding means "Etichal Hacking" they never attack other people in real life. it's all about demonstrated

    • @Zero5309
      @Zero5309 3 года назад

      @@roniwinchester8351 yes but the video title is "Advanced SQL Injection Tutorial". What he showed is the least level of diffidulty possible

    • @roniwinchester8351
      @roniwinchester8351 3 года назад

      @@Zero5309 then learn in google, you can't force anyone to teach you how to hack in real world.

    • @Zero5309
      @Zero5309 3 года назад

      @@roniwinchester8351 ??? What are you even talking about. That's what this channel is all about. He's already showing how to hack. If the title says advanced I dont want to see most basic stuff.

    • @russnemet1158
      @russnemet1158 3 года назад +1

      If you want to see real SQL xss attacks check for bug bounty videos. Or videos of how the winners of a bug bounty won the bounty.

  • @wintorez6649
    @wintorez6649 3 года назад +1

    Thank you sir for making this video 🇮🇳🇮🇳🇮🇳🇮🇳🇮🇳

  • @wealthyDev
    @wealthyDev 3 года назад

    I just understood why my moms movies site account, one year ago got hacked😂 SQL Injection is way too powerfull :)

  • @soumkadi2776
    @soumkadi2776 3 года назад

    In the payload does I can Write just
    SELECT * FROM users ??

  • @sohankhan4042
    @sohankhan4042 3 года назад +8

    Love from Bangladesh 🇧🇩

    • @secretmystery8305
      @secretmystery8305 3 года назад +3

      Nice. look 1st 2 cmt from bangladesh. I think all Bangli Love Hawking Like Me :)

    • @rafin5651
      @rafin5651 3 года назад

      @@secretmystery8305 I am also come from Bangladesh 🙂..

    • @secretmystery8305
      @secretmystery8305 3 года назад

      @@rafin5651 nice :)

    • @rafin5651
      @rafin5651 3 года назад +1

      @@secretmystery8305 yeah ...😁

    • @secretmystery8305
      @secretmystery8305 3 года назад

      @@rafin5651 lets hack uuuuuu 😀😅

  • @sudipdiyasi9647
    @sudipdiyasi9647 Год назад

    Please make a video on sql injection shell upload using sqlmap.

  • @mralien0047
    @mralien0047 3 года назад +1

    Thnq my teacher, you're the best of the best

  • @spacifiasome2229
    @spacifiasome2229 3 года назад

    Love from sri lanka 🇱🇰🇱🇰🇱🇰
    By the way how did you run samsung android framework on windows in previous videos

  • @akashjain3100
    @akashjain3100 3 года назад

    Bro can u plz tell how many langauge we have to know to become network pentester ?

  • @mr.hackme7435
    @mr.hackme7435 3 года назад +1

    Such amazing Hacker ❤️

  • @timotiuslartutul3974
    @timotiuslartutul3974 3 года назад

    Very educational. Thank you for create this Chanel. but honestly, I'm still not very good at understanding English so please help me to provide Indonesian subtitle. i'm from Indonesian btw.🙏🙏🙏🙏🙏

  • @GooDog2906
    @GooDog2906 8 месяцев назад

    your program languague to write this lab ? PHP and MYSQL

  • @aniketjoshi6286
    @aniketjoshi6286 3 года назад +1

    Love ❤️ from India 🇮🇳
    Can i get a heart ??

  • @anydayanymoment6159
    @anydayanymoment6159 3 года назад +1

    Does this work on TEST websites or for real ones? I know few shitty websites and would love to hack it, ?

  • @reahnascent8650
    @reahnascent8650 2 года назад

    But all this attack doesn’t work on live website, why???

  • @LoiLiangYang
    @LoiLiangYang  3 года назад

    What do you think /**/ is for?

    • @d3vast8r
      @d3vast8r 3 года назад

      Commenting things out..

  • @Finnriderlife
    @Finnriderlife 3 года назад

    Can you do a Lesson on Beef / Ngrok / Portforwarding on WAN. Just dont get it working..

  • @ethicmedia3870
    @ethicmedia3870 3 года назад

    wordpress hacking tutorial plzzz

  • @nepaliredteam1713
    @nepaliredteam1713 3 года назад

    Love 💞 from Nepal 🇳🇵

  • @b391i
    @b391i 3 года назад +2

    KEEP GOING MY FRIEND 😎👍

  • @aFynoX
    @aFynoX 3 года назад +1

    Great content😎😎😎 Sir keep it up 👍

  • @xcypher
    @xcypher 3 года назад +1

    Love from indonesian 🇮🇩 :)

  • @Real_delron
    @Real_delron 3 года назад +1

    Thanks been waiting for this..❤️

  • @TalsonHacks
    @TalsonHacks 3 года назад +1

    Quantitys

  • @jamesgray4037
    @jamesgray4037 2 года назад

    Dude my freind u are a legend

  • @Unknown-si8uu
    @Unknown-si8uu 3 года назад +2

    Bro wr are u from

  • @trickshot8653
    @trickshot8653 3 года назад

    if it doesnt work on a website then other sql payloads wont work as well?

  • @prathap304
    @prathap304 3 года назад

    Iam student from India.
    There are no major degree in cybersecurity , where I live.
    Can I take Information technology or Computer Science degree to get started in cybersecurity field??
    Can you give me a suggestion to get started in the field.
    I was more passionate about it...

  • @SathishkumarM
    @SathishkumarM 3 года назад +1

    Great video. Could you please tell me how to test SQLi for below API call? This endpoint support GET, POST and DELETE method also.
    GET /api/v1/user/profile/123.
    If there is any article or video on finding SQLi, XSS, CSRF on API's, please share

    • @br33z49
      @br33z49 3 года назад

      Check for improper access control, You might find some juice

  • @alexxxk
    @alexxxk 3 года назад

    This guy teach so good !!!

  • @chaitu007
    @chaitu007 3 года назад

    Keep upload more videos related to sql

  • @rukshanaaly7794
    @rukshanaaly7794 2 года назад

    so this is union based sql injection sir ?

  • @GlobusZZ
    @GlobusZZ 3 года назад

    Loi how i can get owasp juice shop on my kali ? Am i need to download ova or iso image with running juice shop ?

  • @aliibrahim5479
    @aliibrahim5479 3 года назад

    This depends on the database right? I mean would the query be the same if the website was using a different database and if not then how would you know what query to use? do you just have to keep trying ?

    • @bakedtomatohh807
      @bakedtomatohh807 3 года назад +2

      Check the whatweb data of the website. It will show in the result which database language has been used.

    • @aliibrahim5479
      @aliibrahim5479 3 года назад

      @@bakedtomatohh807 thank u

  • @s.aravindh6227
    @s.aravindh6227 3 года назад +2

    Nice video 👍👍👍

  • @andreasclaudius9076
    @andreasclaudius9076 Год назад

    if i don t have this rest/products ?

  • @Mamuli_28
    @Mamuli_28 2 года назад

    sir pls make sqlmap videos 🙏🏻 thanku

  • @ianmoraga37
    @ianmoraga37 3 года назад +1

    Next: advance server side request forgery

  • @marcush3ll673
    @marcush3ll673 3 года назад +1

    You're great sir !

  • @zekeriya9
    @zekeriya9 3 года назад

    Please sir teach us how to skip 2 steps verification code in gmail please sir

  • @bachtiarmuhammad8716
    @bachtiarmuhammad8716 3 года назад

    If the password is hashed using Bcrypt I think it would be hard to decrypt

  • @_heffen
    @_heffen Год назад

    woooooh amazinf simple tutorial

  • @fmbyts1256
    @fmbyts1256 2 года назад

    what to do if domain is Locked?

  • @zy9ard3
    @zy9ard3 3 года назад

    What is advanced in it?....This is a basic SQL injection.... kindly make video on obfuscating WAF on SQLi

  • @hackwithjack4816
    @hackwithjack4816 3 года назад +1

    Thanks alot mr.sir

  • @forprogramming39
    @forprogramming39 3 года назад

    thank you very much
    you profstional strong

  • @williamgomez6087
    @williamgomez6087 3 года назад

    Master of masters!

  • @ramkanwar9697
    @ramkanwar9697 3 года назад +3

    Awesome 🔥🔥🔥🔥🔥

  • @irinitsouri4074
    @irinitsouri4074 Год назад

    Love that 9:07

  • @devmehta2475
    @devmehta2475 3 года назад

    Is it possible to decrypt password_hash() security ???

  • @jesled5312
    @jesled5312 2 года назад

    How are search engines Hacked

  • @ITZUMYK
    @ITZUMYK 3 года назад +1

    Awesome video!

  • @SharifulIslam-fp4yk
    @SharifulIslam-fp4yk 2 года назад

    What is the use of /**/ in sql statement?

    • @f4hrenheit
      @f4hrenheit Год назад

      It's a replacement for a space character because /**/ is a comment in SQL-Syntax. But it's actually not needed in this case.

  • @TAIRASION
    @TAIRASION Год назад

    My response can be regarded as just as shot in the dark bro as I am still a no-eye deer, hahaha.

  •  Год назад

    What's with the /**/ ??
    All the rest is self-explanatory

  • @yahyabammi5622
    @yahyabammi5622 3 года назад +1

    good tutorial

  • @IgniteMotiverse
    @IgniteMotiverse 3 года назад +1

    Best 👍