Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

50 Ways to Inject Your SQL

Loading...

Sign in or sign up now!
49,020
Loading...
Alert icon
Sign in or sign up now!
Alert icon
There is no Interactive Transcript.

Uploaded by on Jun 14, 2009

A parody of Paul Simon's "50 Ways to Leave Your Lover," but for software security nerds.

Lyrics:
I see your input's not validated properly
You have to check it at all tiers: 1, 2 and 3
Give me a browser and quite soon you will agree. There must be
50 ways to inject your SQL

You see it really is my business to intrude
The CTO wants to see this web app broke into
Turn on my proxy and all doubt will be removed. There must be
50 ways to inject your SQL
50 ways to inject your SQL

Try a quick hack, Jack
Add a new row, Joe
Try an insert, Kurt
Change their SQL query

Evade the regex, Rex
Encode it all in hex
Unbalance the quotes, Vinod
And change the query

Break the syntax, Max
Use a backslash, Cash
Try command shell, Mel,
And change the query

Use "one equals one," son,
Unhandled exception!
Read the stack trace, ace
and change the query

He said our application is secure against your kind
There are no simple vulnerabilities to find
I said your coders write their code like they are blind, there must be
50 ways to inject your SQL

He said our logs show unexpected funds were sent
Its probably time we started using Prepared-Statements
I said I'm glad you're seeing what I meant, there were
50 ways to inject your SQL
50 ways to inject your SQL

Break the syntax, Max
Use a backslash, Cash
Try command shell, Mel,
And change the query

Use "one equals one," son,
Unhandled exception!
Read the stack trace, ace
and change the query

Try a quick hack, Jack
Add a new row, Joe
Try an insert, Kurt
Change their SQL query

Evade the regex, Rex
Encode it all in hex
Unbalance the quotes, Vinod
And change the query

Category:

Comedy

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Top Comments

  • While it won't win any awards for musical prowess, it's damn informative and entertaining.

  • Pfft! Yeah a lot you know music wizard! This song is a contender in The Pwnie Awards for best song. So! There! :p

see all

All Comments (29)

Sign In or Sign Up now to post a comment!
  • FUCK YOU MOVE THE MOUSE

    

  • visit realhackings com to learn all hackings

  • Hahaha, funny and handy.

  • fucking amazing!! 

  • hey POW will be my teacher

  • @rsamberg LOL hey geeks try :P

  • Corny, catchy, funny, and witty......

    Hey, thanks a bunch. Now let me munch...

    on some SQL.

    :)

  • hahahaha awesome!

  • cool

  • Creative! Voice is not all that great, but entertaining.

Loading...
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more