Live Hacking: SQL Injection For Beginners (Part 1)

Ғылым және технология

Sign up for Snyk for free: snyk.co/techraj
Some useful resources on SQL Injection:
snyk.io/blog/sql-injection-ch...
snyk.io/learn/sql-injection/
snyk.io/blog/sql-injection-or...
DISCLAIMER: The demonstration shown in this video is
performed in a controlled lab setup. This video
is for educational purposes only. You can only
perform penetration testing in your own lab
environment and doing it on any live application
is not allowed and it is a crime unless you are a
professional and have appropriate permissions.
In this video, I demonstrated Error-based SQL Injection and by demonstrating it practically on an intentionally vulnerable application called Juice Shop.
OWASP Juice Shop is probably the most modern and sophisticated insecure web application! It can be used in security trainings, awareness demos, CTFs and as a guinea pig for security tools! Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications!
In this video, we exploit the SQLI vulnerability on Juice Shop
Juice Shop: github.com/bkimminich/juice-shop
You can run juice shop on your computer by simply using Docker (check out the above link to read the instructions on how to do so)
Originally, this video was supposed to contain both Error-based SQLI and Blind SQLI, but since the video is getting very long, I had to split it into two parts. This is part 1 that has the Error-based SQLI demo, the part 2 will have the Blind SQLI demo.
I uploaded part 2 to Odysee (LBRY based app) to support the cause of decentralizing the web. Decentralization means no censorship and content freedom!
Unlike platforms like KZread (which are biased and controlled by a central authority), decentralized applications are not controlled by any single authority, no one has excessive powers or privileges over these applications, and most importantly they are also open-source so no data theft!
This is why I believe the decentralized web is the future!
Learn more about LBRY (a content-sharing decentralized application): lbry.com/
Watch Part 2 on Odysee: odysee.com/@techraj156:4/sql-...
If you are new to Odysee, you can use my link to signup: odysee.com/$/invite/@techraj1...
Chapters:
0:00 Disclaimer & What are we going to learn in this video?
1:31 About our sponsors - Snyk
5:06 What is SQL?
5:57 What is SQL Injection?
7:06 SQL Injection on Juice Shop
7:37 Install Juice Shop on your PC with Docker
10:22 Exploiting SQL Injection in the Login feature
18:20 Exploiting SQL Injection in the Search feature
34:39 Using SQL Map to automate SQL Injection
39:35 Error based SQLI vs Blind SQLI
40:31 Using Snyk to find and fix SQL Injection bugs
50:31 End of Part 1
Thanks for watching!
SUBSCRIBE FOR MORE VIDEOS!
Join my Discord: / discord
Follow me on Instagram: / teja.techraj​​​​​
Website: techraj156.com​​​​​
Blog: blog.techraj156.com​

Пікірлер: 264

  • @TechRaj156
    @TechRaj1563 жыл бұрын

    Watch part 2 on Odysee (LBRY based decentralized content-sharing application): odysee.com/@techraj156:4/sql-injection-part2 Also, check out Snyk: snyk.co/techraj

  • @bdas8420

    @bdas8420

    3 жыл бұрын

    Ok after 50 min

  • @krish7021

    @krish7021

    3 жыл бұрын

    What is your qualifications

  • @ayushchampatiray7768

    @ayushchampatiray7768

    3 жыл бұрын

    Would this work in case of a Ajax request where content type is just one string( application/x-www-form-urlencoded)

  • @hemanthsankaramanchi5320
    @hemanthsankaramanchi53203 жыл бұрын

    Need more content like this.

  • @Iuffycs

    @Iuffycs

    3 жыл бұрын

    @📌Pinnedby Tech Raj KZread okay KZread Bot

  • @falconfire8759
    @falconfire87593 жыл бұрын

    the quality of his video- 101% KZread messing with his channel - 2000% result - max 10k viewers :/

  • @itskiller8012

    @itskiller8012

    3 жыл бұрын

    True😢😢

  • @appyviral8753

    @appyviral8753

    3 жыл бұрын

    Apke comment ko yt ne dekha or video ko thoda boost diya 😀

  • @singhisking821

    @singhisking821

    2 жыл бұрын

    @@appyviral8753 lmao

  • @bertrandfossung1216
    @bertrandfossung12163 жыл бұрын

    Raj I can't thank you enough for this beautiful and instructive content on SQL injection. I have learned a tone of new things. We need for content like this especially for bug bounty hunting. Thanks bro!!👍🏽🙏🏽

  • @avijitd22
    @avijitd223 жыл бұрын

    Need this types of videos from you

  • @kaustubhpaturi4801
    @kaustubhpaturi48013 жыл бұрын

    WE NEED MORE!!

  • @akshatdasondhi30
    @akshatdasondhi302 жыл бұрын

    Loved it, need more lessons like this thankyou ❤️🔥

  • @fitnessbro8442
    @fitnessbro84423 жыл бұрын

    Expecting more content like this 🙏🙏🙏

  • @harshitsinghGRIND
    @harshitsinghGRIND3 жыл бұрын

    was waiting for a long time

  • @harshitsinghGRIND

    @harshitsinghGRIND

    3 жыл бұрын

    @📌Pinnedby Tech Raj KZread are you able to see who subscribed you?+ which browser do u love the most?

  • @Abhinav-Bhat
    @Abhinav-Bhat3 жыл бұрын

    Good one I would not see any Indian Course But today I am Proud of You Thank You Anna

  • @kurdmajid4874
    @kurdmajid48743 жыл бұрын

    Dude thanks a lot man ur vids are really informational

  • @hrishikeshmahato4071
    @hrishikeshmahato40713 жыл бұрын

    Very informative as always ❤

  • @bruhhh-__-
    @bruhhh-__-3 жыл бұрын

    There are many videos on SQL and I have learned but not the complete and it's interesting to learn from your favorite KZreadr

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    Thanks for watching... +:1-5-1-6-3-9-9-1-9-1-1 Direct feedback 📥

  • @niveds9090
    @niveds90903 жыл бұрын

    Great content. Expecting more content like this.

  • @vinayakpatil5214
    @vinayakpatil5214 Жыл бұрын

    Underated channel...the incredible way of exploitation explaination, hatsoff dude. keep growning bro.

  • @SinisteR2602
    @SinisteR26023 жыл бұрын

    We want more of these type of videos ! You are doing a great job

  • @HeyAsif
    @HeyAsif3 жыл бұрын

    _Raj_ *Make some great courses please*

  • @isha7359
    @isha73593 жыл бұрын

    I didn't knew that sql can be used for this i thought it was usless while learning it in my class😊 But now😍

  • @NexPlayy

    @NexPlayy

    6 ай бұрын

    🤣🤣🤣🤣

  • @rastgo4432
    @rastgo44323 жыл бұрын

    Great tutorial bro , i hope u'll be making more of these cool content . 👏🏻

  • @priyansh5233

    @priyansh5233

    2 жыл бұрын

    @📌Pinnedby Tech Raj KZread Scammer.

  • @kspavankrishna
    @kspavankrishna3 жыл бұрын

    GREAT VIDEO THANK You FOR MAKING IT

  • @tarunvarma9828
    @tarunvarma98283 жыл бұрын

    We need more content like this more

  • @GauravRai
    @GauravRai3 жыл бұрын

    Most ignored thing in the world : This video's *DISCLAIMER* 😂😂

  • @techrajassistant7317

    @techrajassistant7317

    3 жыл бұрын

    Thanks for your review...... For more information.... contact my recommended broker +1=4=2=3=8=0=1=8=4=0=6 W/H/A/T/S/A/P/P""

  • @DataInNutShell
    @DataInNutShell2 жыл бұрын

    NICE VIDEO BHAI, liked it alot

  • @akshayghoghari1821
    @akshayghoghari18213 жыл бұрын

    very Informative 👍👍

  • @khokon_m
    @khokon_m3 жыл бұрын

    After giving a watch, I downloaded the video. Not sure if youtube removes this one too!

  • @Siddharthtrading
    @Siddharthtrading3 жыл бұрын

    Want more content like this🔥

  • @spy4045
    @spy40453 жыл бұрын

    Dude lot of thanks ❤️ good information

  • @shivangsaraswat315
    @shivangsaraswat3153 жыл бұрын

    You are doing great work please continue this serie..

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    ✓✓T•E•X•T•M•E✓✓ ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓ ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓ A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @shivamanish2280
    @shivamanish22803 жыл бұрын

    Which os should a starter should use windows or linex

  • @SadTown99
    @SadTown992 жыл бұрын

    This channel covers a lot of content that is hard to find accurate information on these days… reminds me of the Wild West internet before everything got nerfed 🤓

  • @rustybolt_
    @rustybolt_2 жыл бұрын

    Frieking luv u man wonderfull explaination Liked and subbed!

  • @ALLISINONE
    @ALLISINONE3 жыл бұрын

    Bro keep it up!

  • @animeloverpakbj8229
    @animeloverpakbj82293 жыл бұрын

    I was just suffering a lot learning SQL injection Thanks a lot 🥺🥺❤️❤️😺

  • @techrajassistant7317

    @techrajassistant7317

    3 жыл бұрын

    Thanks for your review...... For more information.... contact my recommended broker +1=4=2=3=8=0=1=8=4=0=6 W/H/A/T/S/A/P/P""

  • @cyberawm1158
    @cyberawm11583 жыл бұрын

    WoW! I even downloaded this

  • @raahul2813
    @raahul28133 жыл бұрын

    Awesome bro

  • @pratheekshetty.m5784
    @pratheekshetty.m57843 жыл бұрын

    We can also use google cloud docker right?

  • @yasirazam4976
    @yasirazam49763 жыл бұрын

    Bhi aik phone sa dosra phone hack kasy karna hai

  • @hacker-jd6cq
    @hacker-jd6cq3 жыл бұрын

    Nice buddy thank you

  • @radai.
    @radai.3 жыл бұрын

    Literally I love your English

  • @techrajassistant7317

    @techrajassistant7317

    3 жыл бұрын

    Thanks for your review...... For more information.... contact my recommended broker +1=4=2=3=8=0=1=8=4=0=6 W/H/A/T/S/A/P/P""

  • @debashissatpathy5208
    @debashissatpathy52083 жыл бұрын

    First time I found a very usefull sponser.

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    ✓✓T•E•X•T•M•E✓✓ ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓ ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓ A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @vasuparmar9963
    @vasuparmar99633 жыл бұрын

    Which is best for coding and hacking Windows Or Chromebook.??

  • @routetosuccess6716
    @routetosuccess67163 жыл бұрын

    Wow bro you are great 👌

  • @FrpKiller
    @FrpKiller3 жыл бұрын

    Great demonstration

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

  • @ArpanWasti
    @ArpanWasti3 жыл бұрын

    Hello, Can you make video on something like Do's and Dont's for newbies who's have just started to learn? Likewise you said on well equipped environment and such stuffs like Is it safe using my personal emails on the Virtual Box or Dual booted linux distros where I practice injection, penetration tests and stuffs? And other common mistakes? Maybe hope I make some sense here. : )

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

  • @jemilapinto8568
    @jemilapinto85683 жыл бұрын

    My friends Facebook id got hacked how we get that id

  • @gopi9368
    @gopi93682 жыл бұрын

    Thanks!

  • @yashu1089
    @yashu10893 жыл бұрын

    Good content deer

  • @EL-sc9on
    @EL-sc9on2 жыл бұрын

    Instead logging in as the first user in the database, what do I enter to use ORDER BY RANDOM so I login as a random user

  • @_AayushKumar
    @_AayushKumar3 жыл бұрын

    Make a video on blind SQL injection

  • @Knuddelfell
    @Knuddelfell2 жыл бұрын

    love this

  • @shyampandey5546
    @shyampandey55463 жыл бұрын

    We need more content related. To ethical hacking raj big fan of yours

  • @tysonghaly4374
    @tysonghaly43743 жыл бұрын

    Going to the second half

  • @ranjannayak7930
    @ranjannayak79303 жыл бұрын

    Legends be like: *What is SQL* 😅😂

  • @Divaaakar

    @Divaaakar

    3 жыл бұрын

    Structured query language

  • @ranjannayak7930

    @ranjannayak7930

    3 жыл бұрын

    @@Divaaakar yeah 😂

  • @ranjannayak7930

    @ranjannayak7930

    3 жыл бұрын

    @Md golam Mostofa 🤣

  • @b07x

    @b07x

    3 жыл бұрын

    It's like a database managing language

  • @shreayankanjilal

    @shreayankanjilal

    3 жыл бұрын

    @Md golam Mostofa It's easier than programing.

  • @laxmikantsaraswat6319
    @laxmikantsaraswat63193 жыл бұрын

    Part 2🔥🔥🔥🔥🔥bhi aane de jaldi

  • @harshog
    @harshog3 жыл бұрын

    Love from you ♥️

  • @gnanendraprasad1830
    @gnanendraprasad18303 жыл бұрын

    Hi bro there an issue for me how can i contact u

  • @sathwikamin9147
    @sathwikamin91473 жыл бұрын

    Good one

  • @viresh222
    @viresh222Ай бұрын

    Bro this is elite 😮 🎉❤ love from Maharashtra

  • @fluffy280
    @fluffy2803 ай бұрын

    thank u for the video

  • @parrotsec2263
    @parrotsec22633 жыл бұрын

    Good Explanation

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

  • @aniketxcyber2415
    @aniketxcyber24153 жыл бұрын

    need more

  • @quewellschannel6999
    @quewellschannel69992 жыл бұрын

    SNYK same like NMAP?

  • @kshitijkumar9398
    @kshitijkumar93983 жыл бұрын

    Hi teja. Please make a video for a system that records attendance of students entered in meet,the time they remained. Please make

  • @barathkumar588
    @barathkumar5883 жыл бұрын

    Need more videos man...👍

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    Thanks for watching... +:1-5-1-6-3-9-9-1-9-1-1 Direct feedback 📥

  • @adarshranjan2935
    @adarshranjan29353 жыл бұрын

    Please make a video on how to extract drm key 🔑 from drm url

  • @s.kishorekumar8272
    @s.kishorekumar82723 жыл бұрын

    Love you bro

  • @bahai9706
    @bahai97063 жыл бұрын

    10,300th view Lots of love and support from Tripura (North-east)

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    ✓✓T•E•X•T•M•E✓✓ ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓ ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓ A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @xen.sky_8674
    @xen.sky_86743 жыл бұрын

    man i liek your mic can you add the link in desc?

  • @ankitshaw1388
    @ankitshaw13883 жыл бұрын

    Man You are damn talented ❤️

  • @ankitshaw1388

    @ankitshaw1388

    3 жыл бұрын

    @📌Pinnedby Tech Raj KZread I Thought You are also from India

  • @ayushking_01

    @ayushking_01

    3 жыл бұрын

    @@ankitshaw1388 ha ha its fake

  • @pct0679
    @pct06793 жыл бұрын

    Pls Upload 1 video per week

  • @LOLIPOP119Jp
    @LOLIPOP119Jp3 жыл бұрын

    Need more

  • @pratismithgogoi4028
    @pratismithgogoi40283 жыл бұрын

    🔥🔥🔥🔥🔥more more more

  • @coders_algoritmers1032
    @coders_algoritmers10326 ай бұрын

    Sqlmap showing me false positive and unexploitable point detected even vulnerability is available what i do please tell me

  • @ALONE-RIDERN160
    @ALONE-RIDERN1603 жыл бұрын

    Thanks bro 😁

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    W..H..A...T..S...A..P..P..> >>>>>>>>>>>>>>>>>>> +••1••5••1••6•• 3••9••9••1••9••1••1••

  • @mamotechnology2368
    @mamotechnology23683 жыл бұрын

    thank you sir i appreciate the time that you spent to make this video and to teach us these stuffs i really respect you, hope you can teach us ethical hacking well but not on youtube cause , you know there're some rules in youtube that don't allow to share these things

  • @ravindran_1
    @ravindran_13 жыл бұрын

    Sir i wanna learn how to hack color prediction games I need ur help Plz sir help...

  • @ravindran_1

    @ravindran_1

    3 жыл бұрын

    Sir plz help

  • @IM5NFF
    @IM5NFF3 жыл бұрын

    Bro can u plzzz say ur pc specs plzz bro

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

  • @kishanraokumbham5048
    @kishanraokumbham50483 жыл бұрын

    Broo i want resources for learning web security can you plzz help me pointing in right direction I'm confused totally what n where to study and practice plzzxx

  • @techrajassistant7317

    @techrajassistant7317

    3 жыл бұрын

    Thanks for your review...... For more information.... contact my recommended broker +1=4=2=3=8=0=1=8=4=0=6 W/H/A/T/S/A/P/P""

  • @rudradeepdas
    @rudradeepdas3 жыл бұрын

    Can i be a hacker after BCA?

  • @yashu1089
    @yashu10893 жыл бұрын

    lots of love from Russia

  • @Himanshu-Fy
    @Himanshu-Fy3 жыл бұрын

    Sir make a video where we can mining in android via command/running python cudo/nanopool code use via in android make a video this goona be good 🔥

  • @diksha9926
    @diksha99263 жыл бұрын

    Bro can you tell me which headphone you wore?😅

  • @MuhammadSheesAli
    @MuhammadSheesAli3 жыл бұрын

    Tutorial will start at 5:01

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    ✓✓T•E•X•T•M•E✓✓ ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓ ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓ A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @gouravunair9822
    @gouravunair98223 жыл бұрын

    Who needs his hacking course??

  • @_AayushKumar
    @_AayushKumar3 жыл бұрын

    What if login have email validation ? Which query to use for sqli

  • @abhiramam5752

    @abhiramam5752

    3 жыл бұрын

    Use it on password field

  • @_AayushKumar

    @_AayushKumar

    2 жыл бұрын

    It says invalid email

  • @KyrieBron
    @KyrieBron Жыл бұрын

    Brave man

  • @pratheekshetty.m5784
    @pratheekshetty.m57843 жыл бұрын

    Sir please make a video about phoneinfoga

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    T•h•a•n•k•s f•o•r W•a•t•c•h•i•n•g. f•o•r m•o•r•e I•n•f•o o•r g•u•i•d•a•n•c•e W•H•A•T•S•A•P•P +•1•5•1•6•3•9•9•1•9•1•1

  • @GoaBeach988
    @GoaBeach9883 жыл бұрын

    Tq u

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    ✓✓T•E•X•T•M•E✓✓ ✓✓+•1•5•1•6•3•9•9•1•9•1•1✓✓ ✓✓F•O•R•M•O•R•EG•U•I•D•I•A•N•C•E✓✓ A•N•D•I•N•F•O✓✓✓✓✓✓✓✓✓✓

  • @ajay316
    @ajay3163 жыл бұрын

    Mining videos please

  • @suheilyngarciaumana961
    @suheilyngarciaumana9615 ай бұрын

    What happend if I use mongodb ?😮

  • @kartiksavaliya7192
    @kartiksavaliya71923 жыл бұрын

    Uplod more like this

  • @kutral99
    @kutral993 жыл бұрын

    Great raj, expecting contents like this.! 👍

  • @kakinadavala
    @kakinadavala3 жыл бұрын

    Bro raj which company are you working

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

  • @BeHappy-vr1ll
    @BeHappy-vr1ll3 жыл бұрын

    More videos please 🥺🥺🥺

  • @adminbyseregasoleniyminer4490

    @adminbyseregasoleniyminer4490

    3 жыл бұрын

    T•h•a•n•k•s f•o•r W•a•t•c•h•i•n•g. f•o•r m•o•r•e I•n•f•o o•r g•u•i•d•a•n•c•e W•H•A•T•S•A•P•P +•1•5•1•6•3•9•9•1•9•1•1

  • @devarajanp.m2356
    @devarajanp.m23563 жыл бұрын

    Mallus ❤️

  • @neerajkumar-nz4se
    @neerajkumar-nz4se3 жыл бұрын

    Teja bayya tell my name once 😂😂

  • @sloughpacman
    @sloughpacman2 жыл бұрын

    Good video, didn't like the Snyk promo at the end.

  • @TipsFishing343
    @TipsFishing3433 жыл бұрын

    based decentralized content-sharing

  • @UNKNOWNFF04
    @UNKNOWNFF043 жыл бұрын

    Bro my facebook account has been hacked and i tried many times to recover it but it's not recovering can you help me

  • @xxehacker
    @xxehacker3 жыл бұрын

    Bro can you perform on Live website with permission 🙏 . Btw amazing video ❤️

  • @tonystark-ko8bd

    @tonystark-ko8bd

    3 жыл бұрын

    Thats not possible 😂

  • @xxehacker

    @xxehacker

    3 жыл бұрын

    @@tonystark-ko8bd 😂😂

Келесі