SQL Injection Explained

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
19,877
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on May 5, 2011

Watch this video tutorial to find out in simple terms what the SQL Injection vulnerability is, and how real threats result from this typical exploitation.

It features a sample exploitation scenario illustrating clear steps of what an attacker may do with a website which is vulnerable to error based SQL Injection.

Parts 2 and 3 will feature Reverse Shells and Blind SQL injection coming soon...

  • likes, 3 dislikes

Link to this comment:

Share to:
see all

All Comments (17)

Sign In or Sign Up now to post a comment!
  • prolly the best and most informative video on SQL injections I've found. GREAT INTRO!!!

  • nice video btw in a website I get

    Microsoft JET Database Engine error '80040e14'

    instead, is there some other type of injection?

  • @IcaJaBre Mozilla

  • @LelleQ Lol I think he's, or she

  • can you do this to take a specific user id

  • @IcaJaBre Very funny... are you blind?

  • What browser are you using?

  • what your software did you use 4 editig your video

  • @TaylorWalkerKean he is not a lamer that depends on youtube videos to learn "Hacking"

  • @nerosonic He could just know SQL Alot.. And how it all works...

  • @TaylorWalkerKean I was thinking the same thing...

  • Wow, how did you learn all of this?

    

  • @marino3d because in this case the statement would also be ...WHERE username = 'test123' .

    That would work only if there was a real user with that nickname. With the or 1=1 the whole statement is always true regardless of the entered username and gives you access to the first found user in the list

  • How come the 1=1 part is needed? Why wouldn't it work if you just did test123'--. The or 1=1 part seems redundant to me?

  • a very clear tutorial, thanks

Loading...
Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more