Bug Bounty Hunters are WRONG about this‘ OR 1=1

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 พ.ค. 2024
  • Hey everyone! This video is all about SQL Injection. Enjoy!
    🚀 Learn about the easiest bug class here - • Bug Hunting is easy if...
    📩 Download the SQLi Cheat Sheet here - bit.ly/sqli_cheat_sheet
    👍🏻 Like, subscribe, and turn on notifications for more bug bounty insights
    📬 Comment below with your best SQLi payloads
    💻 Happy Hacking!
    Follow me on
    ✖️ - / bughunterlabs
    Thanks for watching,
    BugHunterLabs
    Chapters:
    00:00 - Intro
    00:40 - CVE-2024-2879
    01:20 - SQLi Example
    02:35 - Basic SQLi
    03:09 - Error-bases SQLi
    03:21 - Union-based SQLi
    03:39 - Blind SQLi
    03:48 - Boolean-based SQLi
    04:11 - Time-based SQLi
    04:29 - Out-of-band SQLi
    05:15 - SQLi identification
    05:56 - Wordlists
    06:43 - Advanced Injection Points
    07:47 - Second-order SQLi
    08:22 - sqlmap
    10:27 - Outro
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 35

  • @Horo-oe9yu
    @Horo-oe9yu 27 วันที่ผ่านมา +4

    Coming back to cybersec after a 3 month break, ur videos are indeed worth watching. You definitely earned a subscribtion!

  • @Free.Education786
    @Free.Education786 28 วันที่ผ่านมา +2

    Please cover Ghauri for time based blind SQL injection using only http request with http headers and without headers using custom headers like x-forward-for or similar private headers. Technique also bypass WAF. Hope to see it soon. Thanks 🎉❤

  • @arijit1472
    @arijit1472 29 วันที่ผ่านมา +1

    Great video with Catchy thumbnail. Keep it up man 👍

  • @BLKSD
    @BLKSD 29 วันที่ผ่านมา +1

    I started to addict your videos

  • @TheCyberWarriorGuy
    @TheCyberWarriorGuy 29 วันที่ผ่านมา +1

    Please create a seperate playlist for vulns !

  • @m7mad540
    @m7mad540 29 วันที่ผ่านมา +1

    Yet another incredibly helpful and fantastic video! Your content consistently exceeds expectations. Keep up the excellent work!

  • @abhisheksinha9719
    @abhisheksinha9719 29 วันที่ผ่านมา +1

    Please make a video on SSRF to gain metadata

  • @Ott3rly
    @Ott3rly 29 วันที่ผ่านมา +1

    Very good quality videos. I see that you put a lot of time and effort into this. Keep going!

    • @bughunterlabs
      @bughunterlabs  29 วันที่ผ่านมา

      Thank you! That means a lot! :)

    • @l00pzwastaken
      @l00pzwastaken 29 วันที่ผ่านมา

      I watch both of you thanks both

  • @IncomeMenu
    @IncomeMenu 29 วันที่ผ่านมา +1

    Bro this content is golden. However i feel like you need to work on the thumbnails

    • @bughunterlabs
      @bughunterlabs  29 วันที่ผ่านมา +1

      Thank you. How would you improve the thumbnails?

  • @l00pzwastaken
    @l00pzwastaken 29 วันที่ผ่านมา +1

    Thanks I am learning SQL injection now already completed xss . Thanks for showing how it's performed. What you think about adding Broken Access Control to your video pipeline till .Also thanks for checklist

    • @bughunterlabs
      @bughunterlabs  29 วันที่ผ่านมา

      BAC is on the list :)

  • @confusionofdahighestorda668
    @confusionofdahighestorda668 21 วันที่ผ่านมา

    Nice video bro

  • @MustafaGains
    @MustafaGains 29 วันที่ผ่านมา +1

    Great content

  • @flexboigaming3706
    @flexboigaming3706 29 วันที่ผ่านมา +2

    Next topic CSRF AND OPEN REDIRECT PLEASE ❤

  • @No0ne683
    @No0ne683 29 วันที่ผ่านมา +1

    keep up bro

  • @firzainsanudzaky3763
    @firzainsanudzaky3763 29 วันที่ผ่านมา +1

    hey man, if i dont have burpsuite pro do you think its worth more to focus to sql, ssrf, xss ,or what ? i've found idor and xss bug but xss is out of scope

    • @bughunterlabs
      @bughunterlabs  29 วันที่ผ่านมา +1

      Don't buy Burp Suite Pro until your bounties cover it. There are free tools for everything you need to do out there. Have a look at ZAP and Caido as well. You can even find sql, ssrf, xss with curl and developer tools :)

  • @flexboigaming3706
    @flexboigaming3706 29 วันที่ผ่านมา +1

    Your video content is too good ❤

  • @carsonjamesiv2512
    @carsonjamesiv2512 29 วันที่ผ่านมา +1

    COOL!😀😃😎👍

  • @anonraxor317
    @anonraxor317 13 วันที่ผ่านมา +1

    cheat sheet link not working' or '1'='1--

    • @bughunterlabs
      @bughunterlabs  13 วันที่ผ่านมา

      Hi. It seems to work for me? Did you try: bit.ly/sqli_cheat_sheet

    • @anonraxor317
      @anonraxor317 13 วันที่ผ่านมา

      @@bughunterlabs This content does not exist

    • @anonraxor317
      @anonraxor317 13 วันที่ผ่านมา

      @@bughunterlabs This content does not exist

  • @misero1
    @misero1 25 วันที่ผ่านมา

    Awesome videos you got here im loving the format you got keep up the awesome work. As someone studying cybersec for red team and pentestibg purposes its a great resource.

  • @mtthsgrr
    @mtthsgrr 21 วันที่ผ่านมา

    I'll not say this again kid: where are the half an hour/hour long videos? I need this on my table asap otherwise you're fired

    • @bughunterlabs
      @bughunterlabs  18 วันที่ผ่านมา +1

      Haha. These videos take a long time to make. I will have a look at how I can get to 1 hour.

  • @st3alth_chased643
    @st3alth_chased643 29 วันที่ผ่านมา +1

    Yeah , sometimes sql injection occurs in cookie and user-agent..

  • @Giotheasy
    @Giotheasy 28 วันที่ผ่านมา +2

    meh sql injection is shitty php code only