In this Stream Recording of Late Hacking Night Day 05 (Sinhala), we explore SQL Injection with practical labs from PortSwigger.
Topics Covered:
What is SQL injection?
How SQL injection vulnerabilities occur in web applications
How to identify SQL injection
Exploiting SQL injection types (Boolean-based, UNION-based, blind, error-based, time-based, etc.)
Preventing SQL injection
Labs Demonstrated:
SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
SQL injection vulnerability allowing login bypass
SQL injection attack: querying the database type and version on Oracle
SQL injection attack: querying the database type and version on MySQL and Microsoft SQL Server
SQL injection attack: listing the database contents on non-Oracle databases
SQL injection attack: listing the database contents on Oracle
SQL injection UNION attack: determining the number of columns returned by the query
SQL injection UNION attack: finding a column containing text
SQL injection UNION attack: retrieving data from other tables
SQL injection UNION attack: retrieving multiple values in a single column
Blind SQL injection with conditional responses
Blind SQL injection with conditional errors
Visible error-based SQL injection
💬 Join Heshan Streams WhatsApp Channel for live notifications and events :
https://bit.ly/heshanpererawhatsapp
🌍 Websites :
Main : https://destinyoo.com
Blog : https://blog.destinyoo.com
Portfolio : https://about.destinyoo.com
🎙️ Daily Streams and Content :
/ @heshankperera
‼️ Disclaimer: This content is for educational purposes only. I do not take responsibility for misuse. All material is freely available for those who love cybersecurity, use responsibly and ethically.
#cybersecurity #webhacking #CTF #portswiggerlabs #sinhala