Blind SQL injection with out-of-band data exfiltration (Video solution, Audio)

preview_player
Показать описание
This video shows the lab solution of "Blind SQL injection with out-of-band data exfiltration" from Web Security Academy (Portswigger)

Рекомендации по теме
Комментарии
Автор

Thanks for the solution, however I am still figuring it out... in my Collaborator I only receive DNS querys... but no HTTP... I think i triedeverything. Can you help?

take-AK
Автор

How do you know you have to use XXE payload?

MusicHckrs
Автор

An actual explanation video would be much more useful than this. Solution will not serve anyone good if they don't understand what the hell happened and how this works.

machne