SQL Injection | Complete Guide

Sdílet
Vložit
  • čas přidán 26. 07. 2024
  • In this video, we cover the theory behind SQL injection vulnerabilities, how to find these types of vulnerabilities from both a white box and black box perspective, how to exploit them and how to prevent them.
    ▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
    Web Security Academy Series Course: academy.ranakhalil.com/p/web-...
    Mastering SQL Injection - The Ultimate Hands-On Course: www.udemy.com/course/masterin...
    ▬ Contents of this video ▬▬▬▬▬▬▬▬▬▬
    00:00:00 - Introduction
    00:02:03 - What is a SQL injection vulnerability?
    00:33:44 - How to find SQL injection vulnerabilities?
    00:46:49 - How to exploit SQL injection vulnerabilities?
    01:00:27 - How to prevent SQL injection vulnerabilities?
    01:10:23 - Resources
    01:11:13 - Summary
    01:11:37 - Thank You
    ▬ Links ▬▬▬▬▬▬▬▬▬▬
    Video slides: github.com/rkhal101/Web-Secur...
    Introduction to the Web Security Academy Series video: • Introduction to the We...
    Web Security Academy: portswigger.net/web-security
    Web Application Hacker’s Handbook: Chapter 9 Attacking Data Stores
    OWASP - SQL Injection: owasp.org/www-community/attac...
    OWASP - SQL Prevention Cheat Sheet: cheatsheetseries.owasp.org/ch...
    PentestMonkey - SQL Injection: pentestmonkey.net/category/che...
    Rana's Twitter account: / rana__khalil
    Hacker Icon made by Freepik: www.freepik.com
  • Věda a technologie

Komentáře • 323

  • @RanaKhalil101
    @RanaKhalil101  Před 2 lety +72

    Interested in supporting me and gaining early access to the Web Security Academy videos when they're recorded? Consider buying my course: academy.ranakhalil.com/p/web-security-academy-video-series! ✨ ✨

    • @bigbrain786
      @bigbrain786 Před 2 lety +2

      i don't have money to purchase .

    • @omarc900
      @omarc900 Před 2 lety +6

      @@bigbrain786 $29 save up.

    • @i_youtube_
      @i_youtube_ Před 2 lety

      Is buying the course is intended to support you or there is an additional content added in the paid course.

    • @SauravKumar-if4to
      @SauravKumar-if4to Před rokem

      I don't have money 🥺🥺 so i come here to see

  • @eonraider4180
    @eonraider4180 Před 3 lety +174

    Your video material is actually way better than the instructions provided in the academy itself. The guys at the academy would be crazy not to approach you to incorporate your material into their platform.

    • @RanaKhalil101
      @RanaKhalil101  Před 3 lety +63

      your comment made my day!

    • @eonraider4180
      @eonraider4180 Před 3 lety +14

      @@RanaKhalil101 That's great! I'm glad I found your write-ups too. It's just sheer competence right there. Keep up the good work.

    • @gg-ps1vz
      @gg-ps1vz Před 3 lety +1

      @@eonraider4180 GG twitter.com/PortSwigger/status/1366714766895550469?s=19

    • @comosaycomosah
      @comosaycomosah Před 10 měsíci

      This

  • @Lwyte17
    @Lwyte17 Před rokem +2

    Your material answers all the questions I have when doing the lab's when I think of "what if..." and it really helps complete the whole picture. Will probably sign up soon when I have some time and money!

  • @sporkaccione
    @sporkaccione Před 3 lety +9

    Amazing work, I'm looking forward to the rest of this series!!

  • @kydo2540
    @kydo2540 Před 3 lety +1

    Huge fan! Been following you since the days of your medium writeups. Thank you for your content, you have undoubtedly upgraded my infosec career. Keep doing what you are doing. Hope you continue with videos on this subject matter.

  • @jotunheim1491
    @jotunheim1491 Před 3 lety +3

    Thank you so much, amazing work. Actually it's the most up-to-date work, covering everything from a white/grey/black box perspective. Again, thank you! You are awesome :D

  • @shankaranand7761
    @shankaranand7761 Před 3 lety +3

    Very comprehensive and insightful. Never had anyone explain SQL injection in such a manner. Was very easy to follow through. Thank you. Great work! Awaiting more content.👍

  • @Hendrix312002
    @Hendrix312002 Před 3 lety +1

    This video is incredibly helpful and insightful. I really look forward to the other videos in this series. Thank you!

  • @nOneimportant11192a
    @nOneimportant11192a Před rokem +1

    You are AMAZING! Thank you so much for all the effort and time to bring such an excellent content to the community. You are an inspiration!

  • @logosmaxima2775
    @logosmaxima2775 Před 3 lety +12

    Where have you been all my life? Please continue working on this. This is great!

    • @hilalkhan8446
      @hilalkhan8446 Před měsícem +1

      Yes........ and You comment ( My heart's words).

  • @brunocarrazza500
    @brunocarrazza500 Před 3 lety +2

    Hey Rana! greetings from Brazil!! Thanks for the great work and content you've been putting up. Looking foward to see your next videos!!!

  • @ehabahmedyassen
    @ehabahmedyassen Před rokem +3

    Thank you so much for your amazing course, your effort and your time! I really like the consistency in the slides format & flow of explanation for each topic and how you organise the playlists for each topic with short and long versions 😊

  • @barebears289
    @barebears289 Před 2 lety +1

    You're the best! I love your work, and I have learned a lot from you! You deserve a million subs. Tysm😄

  • @GabrielLawrence_gebl
    @GabrielLawrence_gebl Před 3 lety +1

    This is great. Thanks for doing it. Shared it with my whole team.

  • @absoluteepic1703
    @absoluteepic1703 Před 3 lety +1

    Best explanation I would say, simple and straight! Very helpful, thank you!

  • @dhairyanagda1672
    @dhairyanagda1672 Před 3 lety +4

    Great work! Thank you for doing this. Really means a lot to us beginners❤️ Looking forward to more such informative videos👍

  • @mystriux5676
    @mystriux5676 Před 3 lety

    This is amazing. Your video is really easy to understand and I love it! Please continue working on this

  • @ig101g3
    @ig101g3 Před 3 lety +2

    Your work is amazing!! I’m excited for more content

  • @bakeery
    @bakeery Před rokem +1

    Subhallah! This is what I spend so many months looking for, finally gotten it for free, Thanks alot for the resources.

  • @andrespino8552
    @andrespino8552 Před 2 lety

    Wow. This is gold. Thank you very much for taking the time to make this incredible material.

  • @anonymous6666
    @anonymous6666 Před 3 lety +1

    Oh my goodness. Thanks so much for your hard work, it was super helpful and your video seems professionally made💙

  • @hacktrader29
    @hacktrader29 Před 3 lety +4

    I am totally new to this world , but your video is good to understand. Thanks

  • @mohammadmaniruddin7921
    @mohammadmaniruddin7921 Před 2 lety +1

    Completed the whole video. Going for the next one. Thank you so much for sharing the awesome knowledge ❤️

  • @Aditya-xe3de
    @Aditya-xe3de Před 2 lety +3

    Really appreciate your efforts and time you put into making these tutorials , these are really helpful and qualitative .also expecting Such more tutorials based on the course ahead . again thank you for sharing your knowledge you're giving back to the community in the amazing way.🙌

  • @aaronwhite1786
    @aaronwhite1786 Před 2 lety +2

    I've been studying for the GSEC for work, and it's really taken away time from all of my offensive security studying, but I'm finally sitting down for some free time to study and checking out your tutorials. They've all looked great from the handful I've watched while on in the background while working, but I'm looking forward to really digging in and using them to get ready for the Burpsuite Cert after my GSEC test in December.
    Thanks for all of the hard work!

    • @aaronwhite1786
      @aaronwhite1786 Před 5 měsíci

      Ha! Saw my old comment here and figured I'd update. I got the GSEC checked out, and now I'm back learning all of this all over again since I'm studying for the GWAPT.
      Thanks again for all of the great videos!

  • @davidobber6788
    @davidobber6788 Před rokem

    WOW! Excellent video that clearly explains how we have to think twice (or more) before feeling safe!

  • @davneg01
    @davneg01 Před rokem

    Thanks so much, very clear, appreciate all of your hard work behind the scenes

  • @lizardking5303
    @lizardking5303 Před 3 lety +1

    My new favourite content creator! Thank you so much for this

  • @mian_al_ruhanyat
    @mian_al_ruhanyat Před 7 měsíci

    I always hate theory but your theory videos are so practical that you can't imagine. It's helping me a lot.

  • @mohammedal-shaboti7939
    @mohammedal-shaboti7939 Před 3 lety +1

    Your methodology of testing is great. Well done!

  • @bobbychase5616
    @bobbychase5616 Před 3 lety +1

    so much information!
    will be following with the series

  • @juandaxp3851
    @juandaxp3851 Před 3 lety +1

    Great work!! Thank you for sharing your knowledge. Looking forward to learning a lot through your channel! :)

  • @josekiki1587
    @josekiki1587 Před 3 lety +2

    The great super explanation I deeply loved it and waiting for more series from you.

  • @prabakarj4797
    @prabakarj4797 Před 3 lety

    Wow!! Simply awesome! Finally I found a channel which Deep dive into the SQL injection!

  • @irfanullah9375
    @irfanullah9375 Před rokem

    I am here after watching the Broken access vulnerability topic with David Bombal. The way of your teaching is outstanding and thanks for sharing such a valuable knowledge.

  • @MrNightowl1980
    @MrNightowl1980 Před 2 lety +1

    I think that you and the company you work for are amazing! Thank you for these vids!🙂

  • @neerajkharwar6141
    @neerajkharwar6141 Před 3 lety +1

    thanks for uploading this video I was constantly looking for the resource to study this topic and I finally found this video... it is very helpful

  • @zahidazafar7696
    @zahidazafar7696 Před 3 lety +4

    incredibly impressed this is fantastic

  • @gavinLovesMetallica
    @gavinLovesMetallica Před 3 lety

    Thank you Rana for helping us learn!!! More power to you!

  • @semasema9004
    @semasema9004 Před rokem

    Rana, thank you so much for this video! You explain complex topics so simply and clearly! Great!

  • @esadecimale
    @esadecimale Před 3 lety +1

    Reviewing some of these things to fresh up my memory in order to create my own content on the subject (but in italian), and well, excellently explained, thank you very much!

  • @haziqamzar5332
    @haziqamzar5332 Před 3 lety +2

    Assalammualaykum, greetings from Malaysia. There's so much information. Great work! Looking forward next video.

  • @ragnarlothbrok367
    @ragnarlothbrok367 Před 2 lety +1

    You are doing great job teaching! I wish I could have your determination and attention to detail!

  • @janricmalate6793
    @janricmalate6793 Před 3 lety +1

    Great content, I learned a lot about sqli. I'm looking forward to learn more from your future videos.

  • @suryaasurya2350
    @suryaasurya2350 Před 3 lety +1

    Amazing work. Thanks for providing awesome stuff for free of cost.

  • @panduancloud4699
    @panduancloud4699 Před 2 lety

    This is first youtube video without dislike i have ever seen. NICE and thank you for the tutorials.

  • @daniyalahmed7034
    @daniyalahmed7034 Před 3 lety

    Nicely explained. Great job Rana... Will be following you in entire series.

  • @michaelfarmer16
    @michaelfarmer16 Před 3 lety +1

    This is awesome work thank you for your insight. Keep it up :)

  • @artistepromotionz9183
    @artistepromotionz9183 Před 3 lety

    This is the Best Sql explanation on youtube! Keep up the good work👍

  • @vishalcv3263
    @vishalcv3263 Před rokem +1

    Your teaching methodolgy is really amazing. I have no previous tech experience a complete newbie with some basic knowledge and I completey understand what is being explained. Thank you so much for putting in so much of time and efforts and keep up the good work ma'm.

  • @faux3250
    @faux3250 Před 3 měsíci

    This was extremely helpful! As someone who was a bit lost in the Web Security Academy this helped fill in the gaps so much. Thank you for this!

  • @CodeXND
    @CodeXND Před 3 lety +1

    Thank you for your hard work .. lots of information packed into this video.

  • @KyleRichter23
    @KyleRichter23 Před 3 lety

    I just subscribed. You are very easy to understand and I am excited for more SQL content.

  • @srlsec
    @srlsec Před 3 lety

    Concise and straight to the point

  • @osaze61
    @osaze61 Před 3 lety

    Outstanding information, looking forward to continuing the lectures....Thank you

  • @stabgan
    @stabgan Před 3 lety +2

    Your voice is so soothing. Loved your content. Subscribed

  • @sefaxbounter9456
    @sefaxbounter9456 Před rokem

    Thanks a lot, im watching it another time because its useful !!

  • @syedtajuddin5446
    @syedtajuddin5446 Před 3 lety +1

    Amazing explanation. very clear and right to the point.

  • @xtwisted007x
    @xtwisted007x Před 3 lety +2

    I've enjoyed your previous write-ups but this video is sooo stellar!! I've always struggled with getting a good handle on SQLi in the past and mostly just left it up to the automated tools but this guide has given me a much better approach and methodology to apply to injection scenarios. I really appreciate your efforts and look forward to future videos!

    • @RanaKhalil101
      @RanaKhalil101  Před 3 lety +8

      Thank you! The next 16 videos cover SQLi hands on exercises. By the end of this module, not only will you be become a pro at exploiting SQLi vulnerabilities manually but you'll also learn how to automate the exploitation in python ;)

    • @xtwisted007x
      @xtwisted007x Před 3 lety +1

      @@RanaKhalil101 I started thinking about the flow of a python script for this as you were explaining the boolean-based injection. I'm still a python novice however so appreciate learning new methods. 😁

  • @gokuls3931
    @gokuls3931 Před 3 lety +1

    Loved it.. Pls don't stop this series.. ♥

  • @pauraspatil9314
    @pauraspatil9314 Před 3 lety

    Nicely Explained!
    Thank You!

  • @hanshansli2238
    @hanshansli2238 Před 3 lety

    This was great content, thanks!

  • @SquareZeroGaming
    @SquareZeroGaming Před 3 lety +1

    im glad that i found your channel 1 month ago.. such good content mashallah. keep the contents coming ^_^

  • @rodrigoa.cascao1553
    @rodrigoa.cascao1553 Před rokem +1

    I found out about your work on David Bombal's channel. Your channel is fantastic!

  • @goddiemang5792
    @goddiemang5792 Před 3 lety

    Awesome work Rana !!!!

  • @tourpran
    @tourpran Před 3 lety

    wow going to support this channel till the end !!!

  • @CodeWithComments
    @CodeWithComments Před 3 lety +2

    Nice tutorial. 👍 I wanna see more tutorials from different topics. 😊

  • @JohnDoe-sm7vw
    @JohnDoe-sm7vw Před 3 lety

    Keep up the good work and good looks Chica

  • @MerajKhan-lk2tb
    @MerajKhan-lk2tb Před 3 lety

    Great content,thank you so much👍..after searching a lot of video finally got it right video

  • @siddharthchhetry4218
    @siddharthchhetry4218 Před 3 lety +1

    Thank you for such an awesome explanation :)

  • @debarghyadasgupta1931
    @debarghyadasgupta1931 Před 3 lety

    Big promoter of your amazing content. Thanks for sharing with the community. 🙏

  • @sachinbhatt4487
    @sachinbhatt4487 Před 3 lety +1

    Admirable ❤️

  • @choyanhalder1211
    @choyanhalder1211 Před 3 lety +1

    This video is so important for beginner.Thanks a lot mam for your great initiative.please keep it continuous.

  • @boneitch
    @boneitch Před 2 lety +1

    These videos are so awesome that I'm watching and taking notes on New Year's Eve, and I'm truly enjoying myself. Thank you! (And happy new year!)

  • @malcrack1
    @malcrack1 Před 2 lety

    This was awesome content. Thanks for this one. Soon I will enroll in your course in the website.

  • @RunOs3
    @RunOs3 Před 2 lety

    Thank you for posting just a great and informative video. I hope all your dreams come true.

  • @charlesdanny1824
    @charlesdanny1824 Před 3 lety

    Well done, I am really impressed and a very informative one. Please keep up you good work and expecting more video.

  • @nageshv6476
    @nageshv6476 Před 2 lety

    I just wanna say Thank You!. Your videos are awesome.

  • @ElyT0
    @ElyT0 Před 3 lety

    Thank you so much for this amazing explanation!!!!

  • @samdevatechno
    @samdevatechno Před 3 lety +1

    Great efforts and quality video...Thank you so much..

  • @somebodycommented
    @somebodycommented Před 3 lety +1

    I liked this video even before starting. I love the givers !! Sply rahana I follow you in twitter. Tha ks for sharing your knowledge. Keep going great ! Love you voice too ❤️

  • @xWarPlays
    @xWarPlays Před 5 měsíci

    You are awesome for this!! Thank you!!

  • @abdalrahman_raafat
    @abdalrahman_raafat Před 2 měsíci

    Really great video, thank you

  • @MotuzkoIP
    @MotuzkoIP Před 2 lety

    Great job! Thanks!

  • @guliver1999
    @guliver1999 Před 3 lety +1

    Easy to follow explanation. Great presentation! -:)

  • @zubairsafiii
    @zubairsafiii Před 3 lety +1

    Looking forward to more content from you ❤

  • @fahadbawazir1771
    @fahadbawazir1771 Před 3 lety +1

    MASHALLAH, PROFESSIONAL WAY OF PRESENTATION

  • @paultidwell8799
    @paultidwell8799 Před 3 měsíci

    Thank you, I understand so much better now.

  • @goldtoothgod
    @goldtoothgod Před rokem +1

    Thank you so much.your making this so easy to understand

  • @farisalshareef107
    @farisalshareef107 Před 3 lety

    You know I have never wrote a single comment in CZcams but your videos make me do it . Thank you so much for your video and please keep it up 👏

  • @myoaye6225
    @myoaye6225 Před rokem

    The best instruction on SQL injection!

  • @5ql156
    @5ql156 Před 2 lety

    Thaaank you so much for your videos Rana and the way you make them and time to create them and everything!! much appreciated ♥♥

  • @yamashita8822
    @yamashita8822 Před rokem

    You were definitely made for this ❤‍🔥❤‍🔥❤‍🔥❤‍🔥🔥🔥🔥🔥❤❤❤❤❤❤perfect content

  • @user-oo4on5lg9m
    @user-oo4on5lg9m Před 2 měsíci

    with this guide, its easy to understand SQLI , thank u

  • @hatab0x
    @hatab0x Před rokem

    wow I can't get enough of your videos, especially this one

  • @abubakarahmad8014
    @abubakarahmad8014 Před rokem

    It's just amazing and so informative.
    Thank you so much.☺️👍

  • @tranphuc1121
    @tranphuc1121 Před rokem

    great explanation!

  • @zzzzzzzzZzZZzzzaZzz
    @zzzzzzzzZzZZzzzaZzz Před rokem

    Nice explanation, thank you

  • @dbuludag
    @dbuludag Před 3 lety

    I am looking forward see rest of the content soon

  • @cyberdevil657
    @cyberdevil657 Před 8 měsíci

    This is great thank you so much ^^