SQL Injection - Lab #10 SQL injection attack, listing the database contents on Oracle

Опубликовано: 23 Февраль 2026
на канале: Rana Khalil
8,866
193

In this video, we cover Lab #10 in the SQL injection track of the Web Security Academy. This lab contains a SQL injection vulnerability in the product category field. To solve the lab, we perform a UNION based SQL injection attack on a Oracle database that retrieves the usernames and passwords of all users of the application.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ Contents of this video ▬▬▬▬▬▬▬▬▬▬
00:00​​​ - Introduction
01:11 - Understand the exercise and make notes about what is required to solve it
03:15 - Exploit the lab manually
16:55​ - Script the exploit
40:00 - Summary
40:25​ - Thank You

▬ Links ▬▬▬▬▬▬▬▬▬▬
SQL injection Lab #9 video (previous video):    • SQL Injection - Lab #9 SQL injection attac...  
SQL Injection | Complete Guide (theory video):    • SQL Injection | Complete Guide  
Python script: https://github.com/rkhal101/Web-Secur...
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy Video Release Schedule: https://docs.google.com/spreadsheets/...
Web Security Academy: https://portswigger.net/web-security​
Rana's Twitter account:   / rana__khalil