UNION SQL Injection to Extract Data From Other Tables!

preview_player
Показать описание
👩‍🎓👨‍🎓 Learn about SQL Injection vulnerabilities. In this video, we are going to have a look at a UNION SELECT query to extract data from another database table.

Overview:
00:00 Intro
00:12 Lab overview
01:06 Explaining UNION Query
02:25 Extracting Test Values
03:04 Exploiting Vulnerability
04:06 Conclusion

---

Рекомендации по теме
Комментарии
Автор

您讲的太好了,每次看都有新的收获
You speak so well, every time I read it, I gain something new

落珰
Автор

underrated, Your channel deserves much more.

UltraBoiDanielSalama
Автор

Thanks that was really informative and summarized!!

Whatever-fj
Автор

At 3:00 how do we know there's a column named username and password within the table, what if I want to figure out what the column names are, how do I go about doing that?

draeysta
Автор

nice video, great work! one question: if i understand it correctly you can not get a username and/or password (strings) if the original column is an integer? are there ways around this?

presequel
Автор

You make things look so much easy, Thanks for the content ❤️ Keep the good work ❤️

asaadx
Автор

So, how do i prevent UNION SQL injection?

ianmikael
Автор

%27? user and pass use like that? Why isn't that explained on the site before we do the exercise?... it seems that, for some of these challenges, we are expected to already know how to do this stuff, or see videos like this, tbh.

Not a critique on this video, ofc, which is very informative.

balvsmalvs
visit shbcf.ru