SQL injection attack, listing the database contents on non-Oracle databases - Lab#09

Опубликовано: 26 Март 2026
на канале: Mohd Badrudduja
110
3

In this video, we tackle a SQL injection vulnerability in the product category filter. The challenge requires using a UNION attack to retrieve data from other tables in the database. We’ll demonstrate how to identify the table containing usernames and passwords, determine its structure, and then extract sensitive data. By the end of this video, you'll learn how to bypass authentication and log in as the administrator user.

🔍 Key Skills Covered:

SQL injection exploitation
UNION attack for data retrieval
Identifying database tables and columns
Login bypass using extracted credentials

👉 Goal: Use the retrieved usernames and passwords to log in as the administrator and solve the lab.

#SQLInjection #WebSecurity #Hacking #EthicalHacking #PortSwigger #WebSecurityAcademy #SecurityTesting #CTF #Cybersecurity #BugBounty