In this Stream Recording of Late Hacking Night Day 06 (Sinhala), we explore SQL Injection Part II and Server Side Request Forgery (SSRF) with practical labs from PortSwigger.
Topics Covered:
SQL Injection Labs Continued
Using SQLMap to identify SQL Injection vulnerabilities
What is Server Side Request forgery
How to identify SSRF
Exploiting SSRF types
Preventing SSRF injection
Labs Demonstrated:
Blind SQL injection with time delays
Blind SQL injection with filter bypass via XML encoding
Basic SSRF against the local server
Basic SSRF against another back-end system
SSRF with blacklist-based input filter
SSRF with filter bypass via open redirection vulnerability
SSRF with whitelist-based input filter
💬 Join Heshan Streams WhatsApp Channel for live notifications and events :
https://bit.ly/heshanpererawhatsapp
🌍 Websites :
Main : https://destinyoo.com
Blog : https://blog.destinyoo.com
Portfolio : https://about.destinyoo.com
🎙️ Daily Streams and Content :
/ @heshankperera
‼️ Disclaimer: This content is for educational purposes only. I do not take responsibility for misuse. All material is freely available for those who love cybersecurity, use responsibly and ethically.
#cybersecurity #webhacking #CTF #portswiggerlabs #sinhala