SQL Injection - Lab #18 Visible error-based SQL injection | Long Version

Опубликовано: 13 Март 2026
на канале: Rana Khalil
7,300
188

In this video, we cover Lab #18 in the SQL injection module of the Web Security Academy. This lab contains a SQL injection vulnerability. The application uses a tracking cookie for analytics, and performs a SQL query containing the value of the submitted cookie. The results of the SQL query are not returned.

The database contains a different table called users, with columns called username and password. To solve the lab, find a way to leak the password for the administrator user, then log in to their account.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ 📚 Contents of This Video 📚 ▬▬▬▬▬▬▬▬▬▬
00:00​​​ - Introduction
00:12 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:22 - Navigation to the exercise
01:50 - Understand the exercise and make notes about what is required to solve it
02:36 - Exploit the lab using Burp Suite Professional
15:17 - Summary
15:56 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy Lab Exercise: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil