SQL Injection - Lab #2 SQL injection vulnerability allowing login bypass

Опубликовано: 22 Октябрь 2024
на канале: Rana Khalil
30,537
717

In this video, we cover lab #2 in the SQL injection track of the Web Security Academy. This lab contains a SQL injection vulnerability in the login function. To solve the lab, we perform a SQL injection attack that bypasses authentication and allows us to log into the application as the administrator user.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ Contents of this video ▬▬▬▬▬▬▬▬▬▬

00:00​​​ - Introduction
01:20 - Understand the exercise and make notes about what is required to solve it
02:28​​ - Exploit the lab manually
08:32​​ - Script the exploit
33:00​​ - Summary
33:24​​ - Thank You

▬ Links ▬▬▬▬▬▬▬▬▬▬
SQL injection Lab #1 video (previous video):    • SQL Injection - Lab #1 SQL injection ...  
SQL Injection | Complete Guide (theory video):    • SQL Injection | Complete Guide  
Python script: https://github.com/rkhal101/Web-Secur...
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy: https://portswigger.net/web-security​
Rana's Twitter account:   / rana__khalil