Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

SQL Injection - Walking through walls.

Loading...

Sign in or sign up now!
171,005
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Oct 6, 2006

While this may be 1-2-3 for web application programmers, it is quite revealing for those not involved with web application security on a daily basis. This is an example of how easy it is to bypass client-side security checks and hack your way in.

Category:

Howto & Style

Tags:

License:

Standard YouTube License

  • likes, 17 dislikes

Link to this comment:

Share to:

Uploader Comments (jrhelgeson)

  • could you get traced if you hack a school webite???????? please anser

  • @ToaRBlur - yes, I will hunt you down personally :)

  • @jrhelgeson what you mean, you a pedo are somethink!

  • @ToaRBlur - no, I'm a forensics investigator where I help track hackers down and put them in Jail. You asked: "could you get traced if you hack a school webite????????", my answer was "yes, [that] I would hunt you down personally". The :) meaning that I was joking around.

Top Comments

  • 1) The whole point of the video is to illustrate how an improperly designed web application can be used against you. 2) Yes, while javascript can be disabled in the browser to bypass the validation script, the rest of the site requires the use of javascript. Disabling it entirely would prevent all access to the site.

  • @ToasterAssassin They can be, and are. I suggest you Google the hack on HBGary Federal. The entire company got p0wn3d last month from a SQL injection attack. Pretty serious stuff, even a top security company gets it wrong sometimes.

see all

All Comments (243)

Sign In or Sign Up now to post a comment!
  • you are not going to find any websites that have that bad of scripting anymore.

  • @jrhelgeson oh i was gonna say, have you ever tracked any hackers down?

  • @tyleraverette - there was no next page address that I entered or modified. It was already part of the existing page.

  • @jrhelgeson Thanks man, one more thing when you typed the website in since you'd be viewing it offline how did u get the next pages web address?

  • @jrhelgeson lulz drop him in your botnet. That's what I would do personally.

  • @tyleraverette - if it is not working, then the site may not be vulnerable (yet) :)

    ' or 1=1 --

  • Is there a space between the ' and or and then is there a space after or?

View all Comments »
Loading...
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more