In this lesson we'll see an SQL injection vulnerability allowing us bypass password verification to hack the admin and user accounts.
We discuss in depth how the SQL injection works on how the resultant SQL query is modified.
We then use what we have learned to gain access to a regular user account.
00:00 Intro
00:12 What we know so far...
00:38 SQL injection payload
01:14 Deconstructing the SQL query
05:14 Why the admin account?
05:41 Targetting a user account
07:12 SQL payload for the user account
PLEASE REMEMBER TO ONLY USE THESE TECHNIQUES ON ASSETS YOU OWN OR ASSETS YOU HAVE BEEN GIVEN EXPLICIT PERMISSION TO TEST :)
I am a whitehat hacker and do not have the connections to get you out of jail. :)