SQL Injection - Blind SQL Injection with Time Delays and Information Retrieval

preview_player
Показать описание
Support This Channel
======================

Please like and subscribe, it means a lot!

Please buy me a coffee so I can continue to make content.

My cybersec and webdev training site

Join our Discord

In this Portswigger lab we enumerate usernames and passwords from the underlying postgreSQL database by making use of a time-based blind SQL injection attack.

We demonstrate how to run the attack using Burp intruder but ultimately run the attack using SQLmap since the community edition of Burp throttles attacks made from the intruder tab.

By injecting into the trackingID cookie, we are able to ask the SQL database a range of granular true/false quesitons that slowly enumerates individual characters in the SQL table.
Рекомендации по теме
Комментарии
Автор

Thank you! Much appreciated. Please keep making these

coffeeCatPeanutDust
Автор

Thnx again for a very clear explanation!

Educatd
Автор

Hey, great video. The way you explain things is unparalleled. I was solving this lab and tried your method of using the SqlMap, but sqlmap cannot detect that the database is PostgreSQL. I tried multiple times but nothing is happening, can you help me out ? I did solved the lab using Burp but I want to solve using this also.

ankitchauhan
join shbcf.ru