All-Army Cyberstakes! Dumping SQLite Database w/ Timing Attack

แชร์
ฝัง
  • เผยแพร่เมื่อ 8 ม.ค. 2025

ความคิดเห็น •

  • @greenteadisease
    @greenteadisease 4 ปีที่แล้ว +47

    Dang that sql timing injection technique was beautifully engineered. Always learn something new on this channel.

  • @svampebob007
    @svampebob007 4 ปีที่แล้ว +2

    John Hammond:Hacker. Friend. Security Researcher
    Also John Hammond: Copy paste password in plain text

  • @andycascade
    @andycascade 4 ปีที่แล้ว +5

    That sql time-attack was absolutely awesome!

  • @MattRiddell
    @MattRiddell 3 ปีที่แล้ว +1

    17:00 I would have just got it to rerun a couple of times if it thought it got a match and only print/break if all are true

  • @claudiafischering901
    @claudiafischering901 3 ปีที่แล้ว +1

    Sqlite injection is a little bit difficult BUT you "John Hammond" explain it very well - so I understand it - Thanks for that! ^^

  • @viv_2489
    @viv_2489 3 ปีที่แล้ว

    Really like the manual way to solve problems...nice useful content

  • @zgredfryd
    @zgredfryd 3 ปีที่แล้ว

    Definitely cool! Thanks, John, as always great content!

  • @ExplosiveLizard
    @ExplosiveLizard 4 ปีที่แล้ว

    This was great! Always learning something new from you

  • @ra_dude0
    @ra_dude0 4 ปีที่แล้ว

    That was very well presented. Thanks!

  • @Sawta
    @Sawta 3 ปีที่แล้ว +2

    Most of what was going on in the video was beyond me, for now, but it was neat to see the results towards the end of the video. It's interesting to see what you can do once you have a solid understanding of the technology.

  • @padaloni
    @padaloni 4 ปีที่แล้ว +1

    Another really great video, dude. I'd really love to see a longer vid from you dedicated to teaching python for basic web hacking covering the common modules and common usage. Pretty please :) I'd be keen to pay to see that!

  • @zacksargent
    @zacksargent 4 ปีที่แล้ว +18

    Did you change you password after leaking it? @17:42

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +11

      Ah yes, thank you! And thanks for watching!

    • @abhishekreddypalle6885
      @abhishekreddypalle6885 4 ปีที่แล้ว

      @@_JohnHammond Hahaa
      Wat abt using sqlmap....could u solve it completely using sqlmap?

    • @mrr0r508
      @mrr0r508 3 ปีที่แล้ว

      @@_JohnHammond Instructions unclear. Fell asleep browsing John's photo directory.

  • @padreigh
    @padreigh 3 ปีที่แล้ว +1

    How would you counter this? adding delays to random % of sql queries sounds goofy? query string scanning for selects on metatables describing the database and its tables? sql throtteling per user?

  • @zacksargent
    @zacksargent 4 ปีที่แล้ว

    Thank you! This was very interesting

  • @plebbyplebster9595
    @plebbyplebster9595 3 ปีที่แล้ว +1

    What I don't get: How can you even screw up sanitizing your input like this? Either you are aware of SQL injections and close that gap completely or you aren't - that's what I naively believed until now. Or is it like: A timing attack is sometimes the only way to leverage an SQL injection gap? Anyway, thanks for the video!

  • @ahmedtlili3006
    @ahmedtlili3006 4 ปีที่แล้ว +1

    The best as usual

  • @jimmyd7975
    @jimmyd7975 4 ปีที่แล้ว +1

    Love your videos bro. You probably already know this, but after you typed "mkdir the_sql_always_sucks" then proceeded to type "cd " ... as a shortcut, next you could have typed ALT + "." That allows you to repeat the last argument from the previous command(s). If you keep typing ALT + ".", it cycles through all previous commands. Just a little shortcut I use.

    • @iSuperGeek
      @iSuperGeek 4 ปีที่แล้ว +4

      So a word of the wise: that may work in a terminal (e.g. in GNOME, which I tried and does work) but doesn't work in SSH (at least in PuTTY and SecureCRT, both of which I tried). An alternative that works, however, would be "cd !$". "!$" is a shell expansion that expands to "whatever my last command's last argument was". So in this case, "mkdir the_sql_always_sucks" then "cd !$" and you're there.
      Generally speaking, I would highly recommend getting familiar with shell expansions and string manipulations as they're VERY powerful. People will literally call you "the shell wizard" (it happens at work, I kid you not) if you can master them. They make your job a million times easier too, if used correctly.
      Using !! (last command), !$ (last argument of last command), and !str (last command in history that started with str):
      $ cat /etc/sudoers (permission denied)
      $ sudo !! (expands to "sudo cat /etc/sudoers" as it repeats your whole last command)
      $ sudo cat !$ (also expands to "sudo cat /etc/sudoers", as it repeats your last command's last argument)
      $ cat /etc/hosts
      $ vi some-file
      $ cd somewhere
      $ touch something
      $ !ca (expands to "cat /etc/hosts" since that was your last command that started with "ca")
      Using "{...}" to pass multiple arguments to a command or a loop:
      $ for N in {1..10}; do echo ${N}; done (expands to every number from 1 to 10, and the for loop repeats that many times)
      # cp /etc/sudoers{,.bak} (expands to "cp /etc/sudoers /etc/sudoers.bak" - a fast way to make a backup of a file - because the braces expands to two arguments - one with nothing, and one with ".bak")
      $ ls -ld /{home,etc,opt,tmp,var{,/log{,/secure}}} (expands to "ls -ld /home /etc /opt /tmp /var /var/log /var/log/secure", a more magical way to iterate on the "adding something on the end" aspect of expansions)
      Doing fancy stuff with variables:
      $ LOWERNAME="john"
      $ CAPSNAME="${LOWERNAME^}" (the single caret "^" uppercases the first character to "John")
      $ UPPERNAME="${LOWERNAME^^}" (two carets "^^" uppercases the entire string to "JOHN")
      $ LCAPSNAME="${UPPERNAME,}" (a single comma "," lowercases the first character to "jOHN")
      $ LOWERNAME="${UPPERNAME,,}" (two commas ",," lowercases the entire string to "john")
      $ FQDN="my-server.example.com" (we'll grab JUST the hostname and domain names separately)
      $ HOSTNAME="${FQDN%%.*}" (results in "my-server" as "%%str" removes the longest matching str, in our case "a period followed by anything else")
      $ DOMAIN="${FQDN#*.}" (results in "example.com" as "#str" removes the shortest matching str, in our case "anything followed by a period"
      Sure you can do stuff in awk and cut and whatnot, but shell builtins are just as easy, if not easier.
      And just basic stuff that saves you keystrokes:
      $ > file (if you want to make sure a file is empty, you don't need to echo anything to it; just redirect nothingness to it)
      $ vi !$ (there's that "last argument from last command" thing again)
      $ cd /tmp (make note of where you are, when you issue this; more in the next command)
      $ cd - (this will cd you back to the last directory you were in - it's stored in $OLDPWD)
      $ cd (the "cd" command will cd you to $HOME if no directory is specified)
      Anything you can do to save yourself a keystroke is time saved, when you have to do it tens to hundreds of times a day.
      Anywho... Good luck, happy Linux-ing! :)

    • @cocosloan3748
      @cocosloan3748 4 ปีที่แล้ว

      @@iSuperGeek Nice...Anyway its easier for me to press the "up-arrow" and then Home and type sudo :) Its all I need with my current knowledge

  • @BrainFood155
    @BrainFood155 4 ปีที่แล้ว

    This is pretty awesome!

  • @westernvibes1267
    @westernvibes1267 4 ปีที่แล้ว +14

    That's a pretty strong password john haha

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      Gotta use LastPass ;)
      Thanks for watching!

  • @mccoysebrell630
    @mccoysebrell630 3 ปีที่แล้ว

    John how did you get your sublime to generate the html from python????

  • @jayceslesar7318
    @jayceslesar7318 4 ปีที่แล้ว

    Awesome video

  • @legndery
    @legndery 4 ปีที่แล้ว

    Yeah I am not good at python but I know more about Node.js so made this type of script in nodejs. when you print the current known_data it is so satisfying like ASMR.

  • @curhou2
    @curhou2 4 ปีที่แล้ว

    Really ace again thanks!

  • @tanercoder1915
    @tanercoder1915 4 ปีที่แล้ว +1

    just tried to register on the acictf.com
    It says you have to own special type of email "You can register provided you have an email for one of these domains:*.edu, *.gov, *.mil" .
    is this site only for some security professionals? or how can I get in? any hints?

    • @cocosloan3748
      @cocosloan3748 4 ปีที่แล้ว

      LOL Its for students or people working in government

    • @tanercoder1915
      @tanercoder1915 4 ปีที่แล้ว

      Yeah, I got that.

  • @BrazilMentionedHueHue
    @BrazilMentionedHueHue 4 ปีที่แล้ว

    Wouldn't be faster to try to match each bit from the string?

  • @AnthonyBlakley
    @AnthonyBlakley 4 ปีที่แล้ว

    great video

  • @jakepanda209
    @jakepanda209 2 ปีที่แล้ว

    Hi John, Please tell me how can i access that CTF site

  • @wenzhuding6876
    @wenzhuding6876 4 ปีที่แล้ว

    love ur video very much!!!

  • @sko_
    @sko_ 4 ปีที่แล้ว +1

    good as always :)

  • @FahadAkash
    @FahadAkash 4 ปีที่แล้ว +2

    R.I.P Sqlmap 🤣🤣🤣🤣🤣

  • @mccoysebrell630
    @mccoysebrell630 3 ปีที่แล้ว

    I was today years old when I learned you could good your user agent 😳

  • @therealgunny
    @therealgunny 4 ปีที่แล้ว

    super fun videos

  • @ceemihail
    @ceemihail 4 ปีที่แล้ว

    that was awesome!

  • @tracetv8115
    @tracetv8115 4 ปีที่แล้ว

    Sry maybe that's a dumb question, but what 'Get parameter' firstname' does not to appear dynamic mean?

  • @alfarizi9116
    @alfarizi9116 4 ปีที่แล้ว

    That amazing

  • @cheshire_cat_311
    @cheshire_cat_311 4 ปีที่แล้ว +4

    I'm more interested in how to stop such attack technique

    • @iSuperGeek
      @iSuperGeek 4 ปีที่แล้ว +3

      Stop the underlying vulnerability, SQL injection. This is only possible because the site is vulnerable to SQL injection (the whole " ' OR 1=1; -- " part.

    • @keepercool98
      @keepercool98 4 ปีที่แล้ว

      Right now I can think of two ways:
      1) Escape the input on the query (don’t let ‘, “ and other funny characters even reach it)
      2) Less elegant way, but add an artificial delay to every query, so you inhibit this kind of attack.

    • @abeplus7352
      @abeplus7352 3 ปีที่แล้ว +1

      @@iSuperGeek just use prepared statement

    • @iSuperGeek
      @iSuperGeek 3 ปีที่แล้ว

      @@abeplus7352 Exactly. Rolling your own SQL or encryption these days is asking for trouble.

  • @jacobsan
    @jacobsan 3 ปีที่แล้ว

    Nice

  • @JNET_Reloaded
    @JNET_Reloaded 4 ปีที่แล้ว +1

    wheres the 2 python scripts the 1st to get the table name and the second to get the flag? can you upoload them to your github and post a link to them?

    • @nothingnothing1799
      @nothingnothing1799 3 ปีที่แล้ว

      You could just copy what he types during the video

  • @harshdinani
    @harshdinani 4 ปีที่แล้ว

    Could we just use --random-agent techniques=T --level 5 --risk 3 ??

  • @joeynrg
    @joeynrg 4 ปีที่แล้ว

    Hi John, I installed subl the other day.... didnt realise you had to pay for it. Is it really worth paying for as I see you do use it a lot?

    • @unevalkamlesh387
      @unevalkamlesh387 4 ปีที่แล้ว

      Search online for crack key of sublime text of what version you are

    • @Noah-hk4ec
      @Noah-hk4ec 4 ปีที่แล้ว

      @@unevalkamlesh387 Most of the time the Keys dont Work, just open sublime in Ida or similar and bytepatch the Code thats determining the license

    • @svampebob007
      @svampebob007 4 ปีที่แล้ว

      No just get Atom, some addon do have a subscription model, but they generally don't provide anything worth wile, as a text/code editor it's really good.

  • @jordirivero
    @jordirivero 4 ปีที่แล้ว

    Wow

  • @benjarobin
    @benjarobin 4 ปีที่แล้ว +1

    Instead of brut-forcing for each character, you really should use the dichotomy algorithm.

  • @adtiyamuhammadakbar2711
    @adtiyamuhammadakbar2711 4 ปีที่แล้ว

    dang it i cant understand how this attack works LOL

  • @ir4640
    @ir4640 4 ปีที่แล้ว

    Why couldn't you just dump the table names, like shown in the cheatsheet?

    • @user-pb3nz5po3d
      @user-pb3nz5po3d 4 ปีที่แล้ว +3

      The big twist with the challenge was the fact, that you do not get any output from your injected SQL, that's why he just "assumed" certain values and then used the time it took for the database to return as an indicator whether it was true or not.
      The reason this works:
      When SQL gets a list of conditions linked with AND it will try to look at them one by one. In case the first part of an AND is false, it's no use to check the second condition and will quickly abort. In the case that the first part is indeed true then second part has to be checked which is a "heavy to compute" condition (in this case just generating random data, which just takes a little while).

  • @mattfowler6504
    @mattfowler6504 4 ปีที่แล้ว

    I would buy every million dollar HOME and Sunglasses from this place. --👍@lg0r1thm

  • @emilie1977
    @emilie1977 4 ปีที่แล้ว

    Wow