Running an SQL Injection Attack - Computerphile

preview_player
Показать описание
Just how bad is it if your site is vulnerable to an SQL Injection? Dr Mike Pound shows us how they work.

This video was filmed and edited by Sean Riley.

Рекомендации по теме
Комментарии
Автор

How to avoid jail: "I`ve given myself the permission"

martinpet
Автор

imagine not giving yourself permission to do this on your own website and then you sue yourself, win the lawsuit and then land in prison

barkeeper
Автор

the intro had "<computerphile>" and the outro "</computerphile>"... smart... love the attention to detail

soweliLuna
Автор

Decades ago, my brother named his bowling team "select *". This was in the early days of computers, so there wasn't modern security. The bowling alley printed the statistics, and when his team arrived, the employee presented an entire ream of paper and demanded they choose a different name.

karldavis
Автор

The interviewer thought the text editor was already the hacking part

pandasworld
Автор

Me: Can I SQL Injection Attack your website

Me:Sure

clementella
Автор

..what is illegal? running sql attack or making shitty web apps? Coz my real name is "'; DROP table users; SELECT '"

habiks
Автор

It’s crazy how different my understanding of this video is since the first time I watched it. I watched it back in high school, now I’m halfway through a university degree and have taken web development courses... Funky.

mattshnoop
Автор

alright youtube, this has been in my recommended for 2 years now, ill watch it, you win.

randomuser-vsoe
Автор

I love how he explains things non-pretentiously. It seems a lot of people in the computing field really like to think they're better than everyone else.

bennyboy
Автор

Instructions unclear, NSA is outside my house.

tommytomtomtomestini
Автор

The hacking videos are the best and most interesting for me as comp science student. Keep them coming!

SuperManitu
Автор

The whole computerphile series is just great. Much that I can only see through here, although I speak only moderately English.
Your enthusiasm and your fascination for the topic leaves even a slightly boring topic to last interesting.
And that with every clip.

armonfrohlich
Автор

This is defense against the dark arts for Computer Science

JDSileo
Автор

Imagine naming your child "LIKE'%' UNION SELECT * FROM TABLEBASE" so that when they register its name, you'll get the information on all of the country's database

travispetit
Автор

This is a very well done demonstration! I liked being able to see how it worked in an actual example.

Someone ran one of those scripts on my site to try to hack my database a couple years ago. The only thing it helped me realize is that I needed stronger spam protection, because it left thousands of failed injection comments on one of my pages, haha.

zanzlanz
Автор

So the best defense is to disable the "Search" box

AriannaEuryaleMusic
Автор

Okay YouTube, I'll watch it. Recommending it to me for years.

samuelokirby
Автор

This is the best explanation of SQL injection video ever. I've recommended it to a non-technical friend and he got the info-sec job.

PaulBunkey
Автор

I made a website many years ago, and obviously made sure SQL injection wasn't possible, and I also logged stuff, and I did see some people trying to do SQL injection on my website.

antiHUMANDesigns