No video

SQL Injection | Complete Guide

In this video, we cover the theory behind SQL injection vulnerabilities, how to find these types of vulnerabilities from both a white box and black box perspective, how to exploit them and how to prevent them.
▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Web Security Academy Series Course: academy.ranakh...
Mastering SQL Injection - The Ultimate Hands-On Course: www.udemy.com/...
▬ Contents of this video ▬▬▬▬▬▬▬▬▬▬
00:00:00 - Introduction
00:02:03 - What is a SQL injection vulnerability?
00:33:44 - How to find SQL injection vulnerabilities?
00:46:49 - How to exploit SQL injection vulnerabilities?
01:00:27 - How to prevent SQL injection vulnerabilities?
01:10:23 - Resources
01:11:13 - Summary
01:11:37 - Thank You
▬ Links ▬▬▬▬▬▬▬▬▬▬
Video slides: github.com/rkh...
Introduction to the Web Security Academy Series video: • Introduction to the We...
Web Security Academy: portswigger.ne...
Web Application Hacker’s Handbook: Chapter 9 Attacking Data Stores
OWASP - SQL Injection: owasp.org/www-...
OWASP - SQL Prevention Cheat Sheet: cheatsheetseri...
PentestMonkey - SQL Injection: pentestmonkey.n...
Rana's Twitter account: / rana__khalil
Hacker Icon made by Freepik: www.freepik.com

Пікірлер: 323

  • @RanaKhalil101
    @RanaKhalil1013 жыл бұрын

    Interested in supporting me and gaining early access to the Web Security Academy videos when they're recorded? Consider buying my course: academy.ranakhalil.com/p/web-security-academy-video-series! ✨ ✨

  • @bigbrain786

    @bigbrain786

    2 жыл бұрын

    i don't have money to purchase .

  • @omarc900

    @omarc900

    2 жыл бұрын

    @@bigbrain786 $29 save up.

  • @i_youtube_

    @i_youtube_

    2 жыл бұрын

    Is buying the course is intended to support you or there is an additional content added in the paid course.

  • @SauravKumar-if4to

    @SauravKumar-if4to

    Жыл бұрын

    I don't have money 🥺🥺 so i come here to see

  • @eonraider4180
    @eonraider41803 жыл бұрын

    Your video material is actually way better than the instructions provided in the academy itself. The guys at the academy would be crazy not to approach you to incorporate your material into their platform.

  • @RanaKhalil101

    @RanaKhalil101

    3 жыл бұрын

    your comment made my day!

  • @eonraider4180

    @eonraider4180

    3 жыл бұрын

    @@RanaKhalil101 That's great! I'm glad I found your write-ups too. It's just sheer competence right there. Keep up the good work.

  • @gg-ps1vz

    @gg-ps1vz

    3 жыл бұрын

    @@eonraider4180 GG twitter.com/PortSwigger/status/1366714766895550469?s=19

  • @comosaycomosah

    @comosaycomosah

    10 ай бұрын

    This

  • @logosmaxima2775
    @logosmaxima27753 жыл бұрын

    Where have you been all my life? Please continue working on this. This is great!

  • @hilalkhan8446

    @hilalkhan8446

    2 ай бұрын

    Yes........ and You comment ( My heart's words).

  • @hacktrader29
    @hacktrader293 жыл бұрын

    I am totally new to this world , but your video is good to understand. Thanks

  • @bakeery
    @bakeery Жыл бұрын

    Subhallah! This is what I spend so many months looking for, finally gotten it for free, Thanks alot for the resources.

  • @sporkaccione
    @sporkaccione3 жыл бұрын

    Amazing work, I'm looking forward to the rest of this series!!

  • @Lwyte17
    @Lwyte17 Жыл бұрын

    Your material answers all the questions I have when doing the lab's when I think of "what if..." and it really helps complete the whole picture. Will probably sign up soon when I have some time and money!

  • @jotunheim1491
    @jotunheim14913 жыл бұрын

    Thank you so much, amazing work. Actually it's the most up-to-date work, covering everything from a white/grey/black box perspective. Again, thank you! You are awesome :D

  • @shankaranand7761
    @shankaranand77613 жыл бұрын

    Very comprehensive and insightful. Never had anyone explain SQL injection in such a manner. Was very easy to follow through. Thank you. Great work! Awaiting more content.👍

  • @faux3250
    @faux32504 ай бұрын

    This was extremely helpful! As someone who was a bit lost in the Web Security Academy this helped fill in the gaps so much. Thank you for this!

  • @mrsuli1624
    @mrsuli16244 ай бұрын

    Mashaallah Sister, I'm proud that I learned from you😊❤

  • @007-AML
    @007-AML28 күн бұрын

    Your voice rhythm made me to watch The way you are teaching was really amazing

  • @mian_al_ruhanyat
    @mian_al_ruhanyat7 ай бұрын

    I always hate theory but your theory videos are so practical that you can't imagine. It's helping me a lot.

  • @aaronwhite1786
    @aaronwhite17862 жыл бұрын

    I've been studying for the GSEC for work, and it's really taken away time from all of my offensive security studying, but I'm finally sitting down for some free time to study and checking out your tutorials. They've all looked great from the handful I've watched while on in the background while working, but I'm looking forward to really digging in and using them to get ready for the Burpsuite Cert after my GSEC test in December. Thanks for all of the hard work!

  • @aaronwhite1786

    @aaronwhite1786

    5 ай бұрын

    Ha! Saw my old comment here and figured I'd update. I got the GSEC checked out, and now I'm back learning all of this all over again since I'm studying for the GWAPT. Thanks again for all of the great videos!

  • @choyanhalder1211
    @choyanhalder12113 жыл бұрын

    This video is so important for beginner.Thanks a lot mam for your great initiative.please keep it continuous.

  • @stabgan
    @stabgan3 жыл бұрын

    Your voice is so soothing. Loved your content. Subscribed

  • @vishalcv3263
    @vishalcv3263 Жыл бұрын

    Your teaching methodolgy is really amazing. I have no previous tech experience a complete newbie with some basic knowledge and I completey understand what is being explained. Thank you so much for putting in so much of time and efforts and keep up the good work ma'm.

  • @farisalshareef107
    @farisalshareef1073 жыл бұрын

    You know I have never wrote a single comment in KZread but your videos make me do it . Thank you so much for your video and please keep it up 👏

  • @irfanullah9375
    @irfanullah9375 Жыл бұрын

    I am here after watching the Broken access vulnerability topic with David Bombal. The way of your teaching is outstanding and thanks for sharing such a valuable knowledge.

  • @boneitch
    @boneitch2 жыл бұрын

    These videos are so awesome that I'm watching and taking notes on New Year's Eve, and I'm truly enjoying myself. Thank you! (And happy new year!)

  • @RanaKhalil101

    @RanaKhalil101

    2 жыл бұрын

    This comment made my day! Happy new year!

  • @xtwisted007x
    @xtwisted007x3 жыл бұрын

    I've enjoyed your previous write-ups but this video is sooo stellar!! I've always struggled with getting a good handle on SQLi in the past and mostly just left it up to the automated tools but this guide has given me a much better approach and methodology to apply to injection scenarios. I really appreciate your efforts and look forward to future videos!

  • @RanaKhalil101

    @RanaKhalil101

    3 жыл бұрын

    Thank you! The next 16 videos cover SQLi hands on exercises. By the end of this module, not only will you be become a pro at exploiting SQLi vulnerabilities manually but you'll also learn how to automate the exploitation in python ;)

  • @xtwisted007x

    @xtwisted007x

    3 жыл бұрын

    @@RanaKhalil101 I started thinking about the flow of a python script for this as you were explaining the boolean-based injection. I'm still a python novice however so appreciate learning new methods. 😁

  • @esadecimale
    @esadecimale3 жыл бұрын

    Reviewing some of these things to fresh up my memory in order to create my own content on the subject (but in italian), and well, excellently explained, thank you very much!

  • @ehabahmedyassen
    @ehabahmedyassen Жыл бұрын

    Thank you so much for your amazing course, your effort and your time! I really like the consistency in the slides format & flow of explanation for each topic and how you organise the playlists for each topic with short and long versions 😊

  • @kydo2540
    @kydo25403 жыл бұрын

    Huge fan! Been following you since the days of your medium writeups. Thank you for your content, you have undoubtedly upgraded my infosec career. Keep doing what you are doing. Hope you continue with videos on this subject matter.

  • @brunocarrazza500
    @brunocarrazza5003 жыл бұрын

    Hey Rana! greetings from Brazil!! Thanks for the great work and content you've been putting up. Looking foward to see your next videos!!!

  • @neerajkharwar6141
    @neerajkharwar61413 жыл бұрын

    thanks for uploading this video I was constantly looking for the resource to study this topic and I finally found this video... it is very helpful

  • @zahidazafar7696
    @zahidazafar76963 жыл бұрын

    incredibly impressed this is fantastic

  • @nOneimportant11192a
    @nOneimportant11192a Жыл бұрын

    You are AMAZING! Thank you so much for all the effort and time to bring such an excellent content to the community. You are an inspiration!

  • @panduancloud4699
    @panduancloud46992 жыл бұрын

    This is first youtube video without dislike i have ever seen. NICE and thank you for the tutorials.

  • @almustaphaawakili1049
    @almustaphaawakili1049 Жыл бұрын

    this is NETCLOUTS you are the best teacher i ever have in the world MAY ALLAH grand you with JANNAH

  • @barebears289
    @barebears2892 жыл бұрын

    You're the best! I love your work, and I have learned a lot from you! You deserve a million subs. Tysm😄

  • @mohammadmaniruddin7921
    @mohammadmaniruddin79212 жыл бұрын

    Completed the whole video. Going for the next one. Thank you so much for sharing the awesome knowledge ❤️

  • @fahadbawazir1771
    @fahadbawazir17713 жыл бұрын

    MASHALLAH, PROFESSIONAL WAY OF PRESENTATION

  • @rodrigoa.cascao1553
    @rodrigoa.cascao1553 Жыл бұрын

    I found out about your work on David Bombal's channel. Your channel is fantastic!

  • @paultidwell8799
    @paultidwell87994 ай бұрын

    Thank you, I understand so much better now.

  • @dhairyanagda1672
    @dhairyanagda16723 жыл бұрын

    Great work! Thank you for doing this. Really means a lot to us beginners❤️ Looking forward to more such informative videos👍

  • @haziqamzar5332
    @haziqamzar53323 жыл бұрын

    Assalammualaykum, greetings from Malaysia. There's so much information. Great work! Looking forward next video.

  • @MrNightowl1980
    @MrNightowl19802 жыл бұрын

    I think that you and the company you work for are amazing! Thank you for these vids!🙂

  • @absoluteepic1703
    @absoluteepic17033 жыл бұрын

    Best explanation I would say, simple and straight! Very helpful, thank you!

  • @MrHbk7172
    @MrHbk7172 Жыл бұрын

    Finest Video On SQL Injection on KZread ❤

  • @prabakarj4797
    @prabakarj47973 жыл бұрын

    Wow!! Simply awesome! Finally I found a channel which Deep dive into the SQL injection!

  • @user-vh8ce5gd6v
    @user-vh8ce5gd6v5 ай бұрын

    very interesting, as i've been dealing with such a problem myself (was hacked by ransomware on a university server...) what i don't understand is how you loop over a long hash checking every character: this is classical brute force and should take thousands of years... :)

  • @user-oo4on5lg9m
    @user-oo4on5lg9m2 ай бұрын

    with this guide, its easy to understand SQLI , thank u

  • @EktuTechy
    @EktuTechy2 жыл бұрын

    really amazing content.

  • @SquareZeroGaming
    @SquareZeroGaming3 жыл бұрын

    im glad that i found your channel 1 month ago.. such good content mashallah. keep the contents coming ^_^

  • @ragnarlothbrok367
    @ragnarlothbrok3672 жыл бұрын

    You are doing great job teaching! I wish I could have your determination and attention to detail!

  • @gluonboson
    @gluonboson Жыл бұрын

    This presentation is realy realy useful for beginners or students , it explains every details of the topic and and has example of queries and payloads for real-life stuations . Please keep going to do it for young collegues and students. Thank you for your effort.

  • @davidobber6788
    @davidobber6788 Жыл бұрын

    WOW! Excellent video that clearly explains how we have to think twice (or more) before feeling safe!

  • @mohammedal-shaboti7939
    @mohammedal-shaboti79393 жыл бұрын

    Your methodology of testing is great. Well done!

  • @suryaasurya2350
    @suryaasurya23503 жыл бұрын

    Amazing work. Thanks for providing awesome stuff for free of cost.

  • @Aditya-xe3de
    @Aditya-xe3de3 жыл бұрын

    Really appreciate your efforts and time you put into making these tutorials , these are really helpful and qualitative .also expecting Such more tutorials based on the course ahead . again thank you for sharing your knowledge you're giving back to the community in the amazing way.🙌

  • @GabrielLawrence_gebl
    @GabrielLawrence_gebl3 жыл бұрын

    This is great. Thanks for doing it. Shared it with my whole team.

  • @CodeWithComments
    @CodeWithComments3 жыл бұрын

    Nice tutorial. 👍 I wanna see more tutorials from different topics. 😊

  • @anonymous6666
    @anonymous66663 жыл бұрын

    Oh my goodness. Thanks so much for your hard work, it was super helpful and your video seems professionally made💙

  • @josekiki1587
    @josekiki15873 жыл бұрын

    The great super explanation I deeply loved it and waiting for more series from you.

  • @Hendrix312002
    @Hendrix3120023 жыл бұрын

    This video is incredibly helpful and insightful. I really look forward to the other videos in this series. Thank you!

  • @syedtajuddin5446
    @syedtajuddin54463 жыл бұрын

    Amazing explanation. very clear and right to the point.

  • @davneg01
    @davneg01 Жыл бұрын

    Thanks so much, very clear, appreciate all of your hard work behind the scenes

  • @lizardking5303
    @lizardking53033 жыл бұрын

    My new favourite content creator! Thank you so much for this

  • @ig101g3
    @ig101g33 жыл бұрын

    Your work is amazing!! I’m excited for more content

  • @user-cw7im3cu5i
    @user-cw7im3cu5i7 ай бұрын

    Thank you for your knowledge. You are paving the way to knowledge for ordinary people

  • @CodeXND
    @CodeXND3 жыл бұрын

    Thank you for your hard work .. lots of information packed into this video.

  • @paco6266
    @paco6266 Жыл бұрын

    Buenas tardes Rana, te he conocido gracias a un video que realizaste con David Bombal, y me pareció fantástico y tu super simpatica. Soy una persona normal y corriente, y he tenido recientemente una mala experiencia con una empresa realizando trading, bueno ya te puedes imaginar. Jamás pensé que llegara a ser tan incrédulo. Me gusta mucho como te explicas y lo puedo comprender todo hasta ahora. Nunca es tarde para aprender. Voy a ver que tal empiezo con tus tutoriales y si me llenan como hasta ahora, aportaré al canal de la manera que pueda para que sigamos aprendiendo de tus habilidades. Un saludo.

  • @janricmalate6793
    @janricmalate67933 жыл бұрын

    Great content, I learned a lot about sqli. I'm looking forward to learn more from your future videos.

  • @artistepromotionz9183
    @artistepromotionz91833 жыл бұрын

    This is the Best Sql explanation on youtube! Keep up the good work👍

  • @SauravKumar-if4to
    @SauravKumar-if4to Жыл бұрын

    Great content given by you for who have not enough money to buy course

  • @semasema9004
    @semasema9004 Жыл бұрын

    Rana, thank you so much for this video! You explain complex topics so simply and clearly! Great!

  • @a.sstudio6321
    @a.sstudio63212 жыл бұрын

    Love from Pakistan....simple and easy way of teaching...

  • @andrespino8552
    @andrespino85523 жыл бұрын

    Wow. This is gold. Thank you very much for taking the time to make this incredible material.

  • @guliver1999
    @guliver19993 жыл бұрын

    Easy to follow explanation. Great presentation! -:)

  • @mystriux5676
    @mystriux56763 жыл бұрын

    This is amazing. Your video is really easy to understand and I love it! Please continue working on this

  • @adilhashmi7608
    @adilhashmi76085 ай бұрын

    This is the best...!

  • @goldtoothgod
    @goldtoothgod Жыл бұрын

    Thank you so much.your making this so easy to understand

  • @sefaxbounter9456
    @sefaxbounter9456 Жыл бұрын

    Thanks a lot, im watching it another time because its useful !!

  • @haseebnujum636
    @haseebnujum6363 жыл бұрын

    Don't stop ur class is ✨️✨️✨️✨️🥳🥳😘

  • @2012mrmoh
    @2012mrmoh Жыл бұрын

    مشاء الله عليكي. ربنا يزيدك علم

  • @HumberNum
    @HumberNum2 ай бұрын

    Thank you so much for the great explanation keep going 👏👏

  • @nayeemshaik7867
    @nayeemshaik7867 Жыл бұрын

    Mam i became fan of your work, please reply to my question, how you are able to manage time in making this many hours of lengthy content with great quality. What is your motivation?❤👍

  • @juandaxp3851
    @juandaxp38513 жыл бұрын

    Great work!! Thank you for sharing your knowledge. Looking forward to learning a lot through your channel! :)

  • @bobbychase5616
    @bobbychase56163 жыл бұрын

    so much information! will be following with the series

  • @maveronic2868
    @maveronic286810 ай бұрын

    Thank you Rana for your tutorials. Your explanations are clear and concise and I easily grasp these concepts with ease. I have a question about Boolean-Based Blind SQLi. Is it possible that to optimise the finite brute force of each character, the attacker makes use of binary search to find the character, say instead of (…., 1, 1) = ‘s’, the attacker injects (…., 1, 1) < ‘s’, that’d work right?

  • @chiragagrawal7856
    @chiragagrawal78563 жыл бұрын

    Thanks for sharing the proper content with us. Your voice makes it more attractive to understand 😊👌

  • @yamashita8822
    @yamashita8822 Жыл бұрын

    You were definitely made for this ❤‍🔥❤‍🔥❤‍🔥❤‍🔥🔥🔥🔥🔥❤❤❤❤❤❤perfect content

  • @daniyalahmed7034
    @daniyalahmed70343 жыл бұрын

    Nicely explained. Great job Rana... Will be following you in entire series.

  • @gokuls3931
    @gokuls39313 жыл бұрын

    Loved it.. Pls don't stop this series.. ♥

  • @somebodycommented
    @somebodycommented3 жыл бұрын

    I liked this video even before starting. I love the givers !! Sply rahana I follow you in twitter. Tha ks for sharing your knowledge. Keep going great ! Love you voice too ❤️

  • @saadhamid5609
    @saadhamid5609 Жыл бұрын

    رفعت راس اختي العزيزة

  • @dbuludag
    @dbuludag3 жыл бұрын

    I am looking forward see rest of the content soon

  • @KyleRichter23
    @KyleRichter233 жыл бұрын

    I just subscribed. You are very easy to understand and I am excited for more SQL content.

  • @EIDEID99
    @EIDEID993 жыл бұрын

    Rana for presidency

  • @gavinLovesMetallica
    @gavinLovesMetallica3 жыл бұрын

    Thank you Rana for helping us learn!!! More power to you!

  • @5ql156
    @5ql1562 жыл бұрын

    Thaaank you so much for your videos Rana and the way you make them and time to create them and everything!! much appreciated ♥♥

  • @srlsec
    @srlsec3 жыл бұрын

    Concise and straight to the point

  • @drop8637
    @drop86373 жыл бұрын

    Well done Rana! Awesome the content. Maybe you could put the links of the sources in the description? Cheat sheet, web security, etc? :)

  • @RanaKhalil101

    @RanaKhalil101

    3 жыл бұрын

    Done, thank you for the suggestion!

  • @drop8637

    @drop8637

    3 жыл бұрын

    @@RanaKhalil101 you are amazing ! 👍

  • @asdfghjkl1297
    @asdfghjkl12972 жыл бұрын

    thank you so much,loved your voice and explanation😁😀😀

  • @myoaye6225
    @myoaye6225 Жыл бұрын

    The best instruction on SQL injection!

  • @i_youtube_
    @i_youtube_3 жыл бұрын

    I like your content. You are great instructor. I like your unique voice too. Thank you so much.

  • @xWarPlays
    @xWarPlays6 ай бұрын

    You are awesome for this!! Thank you!!

  • @abdalrahman_raafat
    @abdalrahman_raafat3 ай бұрын

    Really great video, thank you

  • @greyhat430
    @greyhat4307 ай бұрын

    thank you soo much ma'am !!