SQL Injection - Web Security Academy

Опубликовано: 27 Июль 2026
на канале: Kacper Szurek
11,787
321

Web Security Academy to strona, na której w praktyce można przetestować jak wyglądają różnego rodzaju podatności.
W ramach tej serii będę na żywo rozwiązywał laboratoria z SQL Injection, odpowiadał na Wasze pytania a także pokazywał różne ciekawostki i techniki, które mogą się przydać w pracy pentestera.

0:00 Intro
3:21 Informacje organizacyjne
9:33 SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
20:57 SQLMap
33:17 SQL injection vulnerability allowing login bypass
38:26 SQL injection UNION attack, determining the number of columns returned by the query
1:01:31 SQL injection UNION attack, determining the number of columns returned by the query
1:06:08 SQL injection attack, querying the database type and version on MySQL and Microsoft
1:15:35 SQL injection attack, querying the database type and version on Oracle
1:19:23 SQL injection UNION attack, retrieving data from other tables
1:21:47 SQL injection UNION attack, retrieving multiple values in a single column
1:29:03 SQL injection attack, listing the database contents on non-Oracle databases
1:37:33 SQL injection attack, listing the database contents on Oracle
1:43:03 Blind SQL injection with conditional responses
2:07:02 Blind SQL injection with conditional errors
2:12:30 Blind SQL injection with time delays
2:18:32 Blind SQL injection with time delays and information retrieval

🔗Ćwiczenia: https://portswigger.net/web-security
📬Darmowy kurs mailingowy: https://szurek.tv/kurs
📩Newsletter: https://security.szurek.pl/live/
💬Facebook:   / od0dopentestera  
📷Instagram:   / kacper.szurek  
💬Discord: https://od0dopentestera.pl/discord
🔥Ankieta: https://szurek.tv/ankieta
☁️100$ na DigitalOcean (reflink): https://security.szurek.pl/linki/d/