Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

IEFD Ep. 11 - Website Hacking - Sql Injection Part 1

Loading...

Sign in or sign up now!
100,237
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Oct 13, 2007

For Infinity Exists Full Disclosure's first Website Hacking episode, we demonstrate how to exploit a security vulnerability occurring in a website's database to extract password hashes. Sql (Structured Query Language) is a computer language designed for the retrieval and management of data in a system's database. The Attack, known as Sql Injection, manipulates Sql statements before they are sent to the Sql Server, allowing the Attacker to create, change, or retrieve data stored in the database. Sql Injection is a hard concept to understand, so we made a video that encompasses all our knowledge on the subject to make it easier for our viewers to grasp.

Part 1 of 2

http://infinityexists.com/videos/episode11/

Category:

Howto & Style

Tags:

License:

Standard YouTube License

  • likes, 18 dislikes

Link to this comment:

Share to:

Uploader Comments (Gregorpm)

  • You have to be kidding me? An admin with a little bit of knowledge will make sure all the passwords are stored on an external localhost machine with md5 hashes. Your site is a joke

  • @RSaddon: An external localhost machine? I'm assuming you meant a remote host. Well I'm happy to inform you that members of my site have their passwords stored as salted MD5 Hashes on a remote MySql server. The website shown in this video was a clone of my real site with fake hashes. This way actual members don't have their hashes exposed.

Top Comments

  • I honestly hate people like you. Why say "I already knew most of the stuff"...No you didn't. You're just a dickfuck that doesn't know shit. There is nothing wrong with LEARNING.

see all

All Comments (103)

Sign In or Sign Up now to post a comment!
  • @adofri It's just random stuff, that the server doesnt expect to have to return. It either is not there or its an invalid request. ex:

    int(blah)

  • you need to explain why blah? why not halb? or what ever?

  • download havij 1.4.0 version for password sql injection index.php and index.asp

  • there are altot of these type tutorials on kobusvdwalt.blogspot.com

  • I have a tutorial on hacking here watch it itl blow you ur mind

  • Very interesting! I'll be sure to try a number of these out sometime.

  • Use havij. its easier

  • mysql_real_escape_string();

    problem solved.

View all Comments »
Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more