Hacking With SQL Injection Attacks (and Where to Practice Them Safely)

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 ธ.ค. 2016
  • Brian and Jason finally figured out HTML tags, so that got them thinking, what other sinister design lies just under the surface? They called up friend and hacker Jgor, who helps them understand one of the oldest security breaches in the books, the SQL injection.
    We're serious when we say don't try this yourself. You could get into some major trouble! Also, putting together a website yourself? Educate yourself on mitigation strategies and exercise good code hygiene. Don't make a website that ends up being an example for bad code.
    Note: at 8:29, the Modulated Rogue possessed Jason and kept him from accidentally saying the wrong decade.
    -----------------------------------------------------------------
    Additional Information
    Volume 8, Issue 54 of Phrack Magazine
    phrack.org/issues/54/8.html
    The History of SQL Injection on Motherboard
    motherboard.vice.com/read/the-...
    -----------------------------------------------------------------
    Patreon: / modernrogue
    Discord (patron reward): / discord
    MR Articles: themodernrogue.com
    Outtakes & BTS: / scamstuff
    Subreddit: modernrogue.reddit.com
    Merch: shop.themodernrogue.com
    Twitter: / modernrogueshow
    Instagram: / modernrogueshow
    Facebook: / modernrogues
    -----------------------------------------------------------------
    Music used in this episode, in order of appearance:
    "Patience" by B-Side:
    chillhop.bandcamp.com/album/c...
    "Menti" by Moose Dawa:
    chillhop.bandcamp.com/album/c...
    Released by Chillhop: / chillhopdotcom
    -----------------------------------------------------------------
    This episode was made with the help of:
    Brian Brushwood - host -- / shwood
    Jason Murphy - host -- / captainmurphy
    Jgor - guest / research -- / indiecom
    Brandt Hughes - camera operator / editor -- / gatowag
    Bryce Castillo - camera operator -- / brycas
    Max Gillilan - live audio engineer -- / djoldfashioned
  • บันเทิง

ความคิดเห็น • 1.1K

  • @notcamer0n
    @notcamer0n 7 ปีที่แล้ว +170

    At this point I've watched so much "do not do this at home because it's illegal but let's show you how it's done anyways" videos that I wouldn't be surprised if I'm being monitored by the NSA

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +15

      Welcome to the club!

    • @Ginger_bit
      @Ginger_bit 4 ปีที่แล้ว +5

      Remember Grant Thompson...

    • @Ginger_bit
      @Ginger_bit 4 ปีที่แล้ว +1

      ​@
      Was that a...,
      "No, I Don't know who Grant Thompson is. who is that Person? I've never heard of that Person in My life. Please tell Me more?"
      Or A...,
      "Oh God no... Please don't remind Me. It's painful just to think about. Oh God, Why did You Have to remind me, You cruel heartless Human being?"
      Sorry, its hard to convey emotion over text, I'd rather just ask than assume.

    • @sylvie_on
      @sylvie_on 4 ปีที่แล้ว +1

      *my dad starts looking over my shoulder*
      “Do we need to talk to the federal bureau of investigation about this? Or maybe the national security agency?”

    • @asadafs3367
      @asadafs3367 3 ปีที่แล้ว +1

      same

  • @ShannonMorse
    @ShannonMorse 7 ปีที่แล้ว +352

    jgor needs a Hak5 sticker on that laptop.

    • @danielheinen3490
      @danielheinen3490 7 ปีที่แล้ว +13

      Lol you guys should have the modern rogue make a guest appearance. They have the mind of hackers. btw I love the wifi pineapple (*:

    • @itsdarklikehell
      @itsdarklikehell 7 ปีที่แล้ว +9

      i agree on the co host thinggy, you should really join forces.

    • @ShannonMorse
      @ShannonMorse 7 ปีที่แล้ว +19

      Chuck Norris we could show them how to take down a drone with a wifi Pineapple. or something :)

    • @danielheinen3490
      @danielheinen3490 7 ปีที่แล้ว +5

      That would be so cool. I would patreon that all day.

    • @wiltbradley
      @wiltbradley 6 ปีที่แล้ว +2

      You need to do collaboration vids Shannon Morse! I sub to both your channels.

  • @Skult1
    @Skult1 7 ปีที่แล้ว +829

    This channel is going to explode. I'm calling it

    • @nocturnalthing6477
      @nocturnalthing6477 7 ปีที่แล้ว +21

      how much black powder does that require? XD

    • @thenot-sofinalcountdown8453
      @thenot-sofinalcountdown8453 7 ปีที่แล้ว +5

      Makoto Ren needs c4 to blow up best.

    • @moomoo1469
      @moomoo1469 7 ปีที่แล้ว +6

      The Not-So Final Countdown it's fine how to make C4 is the next video knowing this channel

    • @currypuddin6902
      @currypuddin6902 7 ปีที่แล้ว +2

      Nice Profile pic Skullt

    • @kkiwi8559
      @kkiwi8559 7 ปีที่แล้ว

      this is my thought

  • @pipsta
    @pipsta 6 ปีที่แล้ว +124

    We will not attempt *uses incognito tab.

    • @CirobusTv
      @CirobusTv 5 ปีที่แล้ว +5

      Pipsta & Enigma Productions the fuck is that gunna do

  • @Pablitoxd
    @Pablitoxd 7 ปีที่แล้ว +376

    Nothing like seeing a new Modern Rogue video in your feed

    • @mikeyguinness9193
      @mikeyguinness9193 7 ปีที่แล้ว

      Crungus Spungus so true

    • @robdog8087
      @robdog8087 7 ปีที่แล้ว

      Crungus Spungus so ture

    • @colagames3164
      @colagames3164 7 ปีที่แล้ว +2

      Crungus Spungus, FINALLY! SOMEONE SPELT THEIR NAME RIGHT!

    • @tofan505
      @tofan505 7 ปีที่แล้ว

      Crungus Spungus sant det

    • @wolfiemac32
      @wolfiemac32 3 ปีที่แล้ว

      Nothing like seeing a four year old Modern Rogue video in your feed!

  • @joshhill4760
    @joshhill4760 7 ปีที่แล้ว +513

    Hey look modern rouge uploaded a video
    But I need to study
    Its about hacking
    Hell yes, fuck studying

    • @whatiswhatlawl
      @whatiswhatlawl 7 ปีที่แล้ว +7

      Josh Hill I love modern *rouge*

    • @spilledcereals2585
      @spilledcereals2585 7 ปีที่แล้ว +10

      Josh Hill modern rouge is my favorite color

    • @colagames3164
      @colagames3164 7 ปีที่แล้ว +2

      whatiswhat lawl, Rogue*

    • @ZmbieTaco
      @ZmbieTaco 7 ปีที่แล้ว +1

      starting next semester, going to school for cyber network security so this is good to know.

    • @asgarseidel4351
      @asgarseidel4351 7 ปีที่แล้ว

      And Gabriel you spelled 'Spelled' wrong

  • @DarkThor88666
    @DarkThor88666 7 ปีที่แล้ว +7

    I love it how they did the whole show as q&a, one is always prepared with all the info, while other one is totally clueless, it's adorable.

  • @WokeDoinks
    @WokeDoinks 7 ปีที่แล้ว +17

    I feel an emotional connection to Brian because he just gets oddly exited when it come to fastening weapons of minor destruction and when it comes to cool " spy stuff" like lock-picking number stations and hacking😂

  • @Nate-gi7no
    @Nate-gi7no 7 ปีที่แล้ว +74

    There is a special string you can type into google to get a list of all sites that have a PHP parameter in them, for which you can test all them by hand until you find one is vulnerable, and run the tool (such as sqlmap or sqlninja), where you can compromise the db. This entire process could take you max 20 minutes, its pretty scary how easy it is to do and how easy it is to prevent. Take this code, for example
    $sth = $dbh->prepare("SELECT * FROM users WHERE username =".$_POST["username"]." AND password = ".$_POST["password"]);
    $sth->execute();
    What the above (PHP) code does is it takes the post parameters (post parameters are usually just data from forms you fill out) and just concatenates the strings together, combining the data, which is what causes it to be vulnerable. To fix this, this is literally all you need to do:
    $sth = $dbh->prepare("SELECT * FROM users WHERE username = :username AND password = :password");
    $sth->bindParam(":username", $_POST["username"]);
    $sth->bindParam(":password", hash("sha256", $_POST["username"]));
    $sth->execute();
    This will now "bind" the data to the tokens in the original string, in this example it is :username and :password. then we run the "bindParam" method to tell PDO that this is where the data will go, and it will not be able to escape this. The above code is 100% secure.
    Lazy developers all around, always make sure you hire reputable ones.

    • @aejae15030
      @aejae15030 4 ปีที่แล้ว +3

      Wow.

    • @mihan2d
      @mihan2d 3 ปีที่แล้ว +3

      Am I the only one who was reading this in Tom Scott's voice? :D

  • @1973Washu
    @1973Washu 7 ปีที่แล้ว +47

    And now we will have people naming their son "Robert'); DROP TABLE students;--" to mess with the school database.

    • @EstrelSteel
      @EstrelSteel 7 ปีที่แล้ว +3

      1973Washu xkcd 327

    • @Dagbass
      @Dagbass 7 ปีที่แล้ว +7

      1973Washu set.grades:F=A>grades>all.set:A

    • @LiEnby
      @LiEnby 7 ปีที่แล้ว +1

      dude this allready happens alot.. >_

    • @tobychow4761
      @tobychow4761 7 ปีที่แล้ว +2

      haha nice reference

    • @lokeshreddy3418
      @lokeshreddy3418 6 ปีที่แล้ว +4

      Update schoolname.school_greades
      Set grade='A+'
      Where class = and roll_no=

  • @famousamos9060
    @famousamos9060 7 ปีที่แล้ว +23

    You guys really don't get the credit you deserve. You are one of my favorite channels to watch.

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +8

      thanks so much. Help spread the word?

    • @famousamos9060
      @famousamos9060 7 ปีที่แล้ว +3

      I sure will. It's just weird after being on The King of Random you'd think there would be a large boost.

  • @MrAlucardDante
    @MrAlucardDante 7 ปีที่แล้ว +48

    Saying SQL like sequel sounds so weird to me, I've always said it like an acronym

    • @kieranbarker1902
      @kieranbarker1902 4 ปีที่แล้ว +2

      I believe what you do, as do I, is the correct way. Just saying the letters. But a lot of people do say "sequel"

    • @TrekkerMoto
      @TrekkerMoto 4 ปีที่แล้ว +2

      Same thing with people who say "Deedoss". That is not the correct way to say it because an acronym is said letter by letter.

    • @pistolpeet5325
      @pistolpeet5325 4 ปีที่แล้ว +1

      The original version of the language was called SEQUEL, so there is some remnants of people that pronounced it "See-Qual" but most people that actually use it today say "S-Q-L".

    • @kutsen39
      @kutsen39 3 ปีที่แล้ว +2

      My teacher always called it squirrel

  • @ironweaselsbest
    @ironweaselsbest 7 ปีที่แล้ว +14

    "hey Dan, how do I become a badass?"
    "alright jimbo, take a look"
    *shows jimbo thr modern rogue*
    *jimbo comes back with a full zztop beard, mutton chops, a glass of whiskey and two named women*

    • @Ginger_bit
      @Ginger_bit 4 ปีที่แล้ว +6

      Yeah, I'd be a little concerned if they were Unamed Women.

  • @Epicmonk117
    @Epicmonk117 7 ปีที่แล้ว +7

    This is the kind of thing that made me decide to go to school for Computer Science and cybersecurity

  • @NikolajLepka
    @NikolajLepka 7 ปีที่แล้ว +3

    I believe the original version of the database language was called "QL" for "Query Language", and then someone came along and made "SQL" or "Structured Query Language" and said it should be pronounced "Sequel" as a jab at QL

  • @MKollerSMS
    @MKollerSMS 7 ปีที่แล้ว +2

    I spent some time working as a Test Admin for a school, and one of my tasks was to upload student demographic info into state testing databases. We pulled the data from Access/Aeries, exported it into Excel, moved some things around and then uploaded the final tables as CSV files. Some of the fields would have to be inputted manually, and we were told to be extremely careful because the testing programs (SBAC's test loader, for example), would execute commands based on the entries of certain fields. It's a little insane when you realize that the input data of one person, if tampered with to look like a command, can adversely affect all entries which follow it.

  • @JBasedGaming
    @JBasedGaming 7 ปีที่แล้ว +20

    the only channel i check daily to see if they have uploaded.

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +1

      oh, man... hang in there. for now we're friday mornings only.

    • @JBasedGaming
      @JBasedGaming 7 ปีที่แล้ว +2

      hope that didn't sound negative. I meant it as a positive because I love your guys channel!

    • @Alex-qj6ij
      @Alex-qj6ij 7 ปีที่แล้ว

      is it illegal to try it out on the login that was in the video

    • @JBasedGaming
      @JBasedGaming 7 ปีที่แล้ว

      PhAnToM .04 no it was setup for you to see how it worked

  • @p4dst3r
    @p4dst3r 7 ปีที่แล้ว +20

    Rights guys, I have now binge watched all of the vids so I need you to pick up the pace and make 25 videos a day.
    Cheers 😉

  • @mic4261
    @mic4261 7 ปีที่แล้ว

    probably some of the best content on youtube nowadays. loving this channel, amazing quality stuff

  • @TonseiSensei
    @TonseiSensei 7 ปีที่แล้ว

    This is probably my favorite youtube channel at the moment. The chemistry between Brian and Jason is amazing, i could watch them all day long, non stop. And they're so funny! Keep it up guys! Cheers from Finland :D

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว

      Thank you! Glad you're enjoying it!

    • @jackolsen5250
      @jackolsen5250 7 ปีที่แล้ว

      Jason Murphy chemistry, ooooooo

  • @techtothemax7352
    @techtothemax7352 7 ปีที่แล้ว +15

    The Modern Rogue is officially my favorite channel on you tube HANDS DOWN

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +12

      Woohoo!!

    • @techtothemax7352
      @techtothemax7352 7 ปีที่แล้ว +1

      Jason Murphy
      HOLY CRAP YOU REPLIED OMG!!

    • @cynicaltrash4967
      @cynicaltrash4967 7 ปีที่แล้ว

      Jason Murphy
      Does anyone know what laptop that is? It looks sleek and I need a new PC.

  • @danielgrimes8225
    @danielgrimes8225 7 ปีที่แล้ว +7

    Awesome guys! Just re-watched Hacking the System and enjoyed it so much! Re-watched Brian on Penn and Teller too! Great job Brian, Love the work

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +4

      thanks, man!

    • @sweliam1
      @sweliam1 7 ปีที่แล้ว

      OmegaReaper His face is public domain, just use a royalty-free photo.

  • @slonismo
    @slonismo 7 ปีที่แล้ว

    Why can't I subscribe to you guys more than once? This is literally in my top 2 favorite channels on TH-cam and you guys certainly deserve more recognition. Rock on!!!

  • @Whacks
    @Whacks 7 ปีที่แล้ว

    You guys are awesome! I love that there is a variety of content and that not only one topic is being focused on. :)

  • @ismaelgoldsteck5974
    @ismaelgoldsteck5974 7 ปีที่แล้ว +9

    0:55 the hacker nearly cringed

  • @arminsantiaguel3434
    @arminsantiaguel3434 7 ปีที่แล้ว +66

    whatever happened to the Ancestry thing??

    • @jeonwooki
      @jeonwooki 7 ปีที่แล้ว +2

      yeah

    • @saxmegal7912
      @saxmegal7912 7 ปีที่แล้ว

      Armin Santiaguel it takes 6-10 weeks to process

    • @shocko9017
      @shocko9017 7 ปีที่แล้ว +4

      +saxmegal the video last week said "results next week"

    • @BrandtHughes
      @BrandtHughes 7 ปีที่แล้ว +10

      It got postponed last minute, it's ready to go for next week though!

    • @arminsantiaguel3434
      @arminsantiaguel3434 7 ปีที่แล้ว

      nice

  • @jowge6759
    @jowge6759 7 ปีที่แล้ว +2

    Damn I was watching MR videos wishing there were more, back out to YT home page and BAM! There is another uploaded 25 mins ago!
    Love your videos!
    EDIT: Side note, after watching the video, I had been interested in SQL for a while but could never understand it. This literally crystally cleared things up for me! Thanks!

  • @rasmus2157
    @rasmus2157 7 ปีที่แล้ว

    Been here since first video man been In love ever since this channel is going to be massive bro!

  • @mr.piebro9010
    @mr.piebro9010 7 ปีที่แล้ว +5

    It's always a great time when you're watching a Modern Rogue video.

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +11

      I can only hope you guys have as much fun watching as we do filming them.

    • @Alex-qj6ij
      @Alex-qj6ij 7 ปีที่แล้ว

      you have the best job in the world. same as the mythbusters

  • @Dexter101x
    @Dexter101x 7 ปีที่แล้ว +58

    Is it ok to test my own security with this hack? localhost is what I mean

    • @brenine3104
      @brenine3104 7 ปีที่แล้ว +26

      plezx29 Yeah, as far a I know. Just like you can't be arrested for breaking into your own house.

    • @Dexter101x
      @Dexter101x 7 ปีที่แล้ว

      OK, I have tested the security, this hack doesn't work, so all secured :)

    • @Dexter101x
      @Dexter101x 7 ปีที่แล้ว +5

      That means he proved that he was the owner, so he was never charged or prosecuted, he was able to prove it. It would of been different obviously f he was a burglar to a property he didn't own

    • @onyxtay7246
      @onyxtay7246 7 ปีที่แล้ว +11

      Aaron Ullger Why should it be illegal to hack your own network? It'd be like breaking into your own house to see how a thief would.

    • @wonderingAroundtoNoWhere
      @wonderingAroundtoNoWhere 7 ปีที่แล้ว +1

      it's perfectly ok to check your own local host, and to check just sent a special character in the programming language, (which ever you are using) and if it does not return an error which belong to server, you are 90% save, i have vedio explaining just that, and more if you like you can check them out

  • @Nerofur
    @Nerofur 7 ปีที่แล้ว +1

    back when I was interested in this kind of stuff I never really understood how to actually do any of it, by far this video has had the easiest and most simple explanation how how to do a basic SQL injection hack

  • @dennyjames2188
    @dennyjames2188 7 ปีที่แล้ว

    I love episodes like this. The ones that actually teach you how to do something truly bad ass. (Or how to make weapons)

  • @GoldenGunner111
    @GoldenGunner111 7 ปีที่แล้ว +3

    I would really like to show my thanks and acknowledgement to Brandt Hughes, Bryce Castillo and Max Gillian. If you ever see them around, could you send them my regards? Or if they're here in the comments, thanks for your work!

  • @erio2352
    @erio2352 7 ปีที่แล้ว +4

    the guy who started talking in the beginning i feel like ive seen him i think from the king of random

    • @erio2352
      @erio2352 7 ปีที่แล้ว +5

      i think his name is ryan rushwood

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +6

      the rodcaster?

    • @sdcard9649
      @sdcard9649 7 ปีที่แล้ว

      The Modern Rogue LOL he is new I think so he'll probably not understand the joke

  • @gogodr
    @gogodr 7 ปีที่แล้ว

    I am impressed Brian, for someone who is not really hacker savvy, you did your homework. Spot on with the questions there.

  • @arndegothia1412
    @arndegothia1412 7 ปีที่แล้ว

    Need to leave a mark for when this channel gets REALLY big. I was here the 30th December 2016.

  • @twistedsymphony
    @twistedsymphony 7 ปีที่แล้ว +14

    Long time Scamschool subscriber and love your stuff but as someone who works with SQL daily there are a few incorrect things here. In the beginning of the video Jason kept referring to "SQL" as a program, where it's really a language that is used to access the data in a number of different database programs (MySQL, SQL Server, etc.). Also the code modification you put up @5:19 is not what would be modified in an injection attack. it's the query string that is being compromised not the connection string.

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +10

      Yeah, sorry. My jargon was definitely off on this one.

    • @twistedsymphony
      @twistedsymphony 7 ปีที่แล้ว +7

      Jason Murphy I love that you guys are tackling these kinds of topics. Looking forward to see what other stuff you have planned in the future.

    • @BrandtHughes
      @BrandtHughes 7 ปีที่แล้ว +2

      re: code modification - Editor here, that example was me painting in broad strokes to teach the larger concept than give a specific accurate example (which, as someone who doesn't code, I wouldn't be able to provide anyway.) Originally it was all more obscured in mosaic to imply that the code itself isn't what mattered there, more than maybe structure or syntax, but when I realized a password field needed to be legible to communicate that structure, the whole thing got less mosaic'd as consequence.

    • @twistedsymphony
      @twistedsymphony 7 ปีที่แล้ว +1

      Abstracting it is fine, my gripe was more about the fact that you showed a very specific piece of code and then showed the modification to the wrong part of it. It was analogous to making a video about how to change out a flat on your car, and when you got to the part about removing the wheel: showing someone removing the steering wheel.

    • @BrandtHughes
      @BrandtHughes 7 ปีที่แล้ว +2

      I think I see now, would it have had to be in the query line? As a laymen it's pretty easy to misinterpret when you see another line specifically referencing passwords and user ids. An unfortunate artifact of us covering a wide variety of topics, is that I, as the person who has to visually explain everything, can only be proficient in so many of those topics.

  • @moshill1374
    @moshill1374 7 ปีที่แล้ว +4

    What was the prequel to SQL?

    • @sweliam1
      @sweliam1 7 ปีที่แล้ว +14

      Moshil l PRQL

    • @CvnDqnrU
      @CvnDqnrU 6 ปีที่แล้ว

      QUEL

  • @alpertugrulcelik211
    @alpertugrulcelik211 7 ปีที่แล้ว

    I love your videos, they are so well done. I think you are highly underrated

  • @Echosaint
    @Echosaint 7 ปีที่แล้ว

    Ah! My three favorite Texans talking about a subject I understand. Good way to end out the year.

  • @Sage-ij6ml
    @Sage-ij6ml 7 ปีที่แล้ว +49

    Wait, is this Brian from scam school?

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +18

      of course!

    • @crawlspace9750
      @crawlspace9750 7 ปีที่แล้ว +4

      Euritide no, it's Brian from Penn & Teller Fool Us ;)

    • @andyloescher2401
      @andyloescher2401 7 ปีที่แล้ว +1

      I love the modern rouge

    • @aa48970
      @aa48970 7 ปีที่แล้ว +3

      Euritide yes

    • @colagames3164
      @colagames3164 7 ปีที่แล้ว

      Andy Loescher, Rogue*

  • @ComputersAreRealCool
    @ComputersAreRealCool 7 ปีที่แล้ว +4

    Is it an American thing to pronounce it "sequel"? Over here in the UK, I've been doing CS for about 5 years now, worked with many programmers and everybody has always pronounced it SQL...

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว

      english.stackexchange.com/questions/7231/how-is-sql-pronounced

    • @ComputersAreRealCool
      @ComputersAreRealCool 7 ปีที่แล้ว

      The Modern Rogue Wow I never knew that, thanks for the info!

    • @applefanXXX
      @applefanXXX 7 ปีที่แล้ว

      Its like GUI or Goo-ey
      Call it whatever you like

    • @KeKsEfReSsEr200
      @KeKsEfReSsEr200 7 ปีที่แล้ว

      ...well, been working as an administrator for almost 10 years now it'll always be SQL for me^^

  • @averylambert9529
    @averylambert9529 7 ปีที่แล้ว

    Loved your guys' show on Netflix, absolutely love the channel. Keep em coming!

  • @richiskinner9810
    @richiskinner9810 7 ปีที่แล้ว

    I love this. Please make it a continuing format on the MR. Yeah, that would be great XD

  • @leano2419
    @leano2419 7 ปีที่แล้ว +5

    Many games and so on just forbid to use ";" and so on in usernames... Esay protection against the example.

    • @xavierh.5102
      @xavierh.5102 7 ปีที่แล้ว +1

      yeah, never understood that until now. seems like an easy fix.

  • @Snowy811
    @Snowy811 7 ปีที่แล้ว +7

    I wonder if brian responds to non derverving comments

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +22

      Depends on how verving they are at the time.

    • @DarthTrazyn
      @DarthTrazyn 7 ปีที่แล้ว

      The Modern Rogue If I have an account with a certain website and I use a SQL injection on my own account with the intent of seeing if the site is vulnerable is that still a felony?

    • @UK-oq2fr
      @UK-oq2fr 7 ปีที่แล้ว

      love u brian i have been watching i 4years

    • @danielheinen3490
      @danielheinen3490 7 ปีที่แล้ว

      Braidborn ..Yes. Unless you own the website then you are breaking the law. Also there are different types of sql injection such as blind / time based

  • @spazgorillamc
    @spazgorillamc 7 ปีที่แล้ว +1

    This is the type of videos I love! this is so much more interesting than mixing drinks XD keep it up guys and thanks

  • @edsonlopez5068
    @edsonlopez5068 7 ปีที่แล้ว +1

    This channel is soon gonna have millions, I'm glad I was here since 150k

    • @mastertrey4683
      @mastertrey4683 7 ปีที่แล้ว

      same i been here since 40k just a couple weeks before grant thompson featured them on his channel

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +9

      I don't want to brag, but I've been here since 0. :P

    • @mastertrey4683
      @mastertrey4683 7 ปีที่แล้ว

      Jason Murphy dangit u beat me

    • @gunnargoestothemovies491
      @gunnargoestothemovies491 7 ปีที่แล้ว

      Been here since -5

  • @humanoid251
    @humanoid251 7 ปีที่แล้ว +5

    Most of the professors at my university don't care if we students see their usernames when they log into things *cracks knuckles* time to hack into teacher accounts
    Just kidding I wouldn't do that. Prison is scary

  • @mr.quarantine5977
    @mr.quarantine5977 7 ปีที่แล้ว +7

    4:12 how did they not make a joke?

  • @estevaoavillez
    @estevaoavillez 7 ปีที่แล้ว

    The voice over in 8:28 is funny! Good video guys!

  • @brandonuniverse
    @brandonuniverse 7 ปีที่แล้ว +1

    this channel deserves to blow up

  • @CWGminer
    @CWGminer 7 ปีที่แล้ว +5

    oh my god... so tempting... must resist...
    *five minutes later* dammit can't resist
    kidding

  • @AlexSilva-gp3ti
    @AlexSilva-gp3ti 7 ปีที่แล้ว +4

    No more porcupine head

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +11

      whoa... where you been?

    • @AlexSilva-gp3ti
      @AlexSilva-gp3ti 7 ปีที่แล้ว +3

      The Modern Rogue Scam school xD

  • @kartoffelkurt3905
    @kartoffelkurt3905 7 ปีที่แล้ว

    Love the vids. Keep up all of the good work

  • @kantana57
    @kantana57 7 ปีที่แล้ว

    Modern rogue is easily one of the best put together series on TH-cam.

  • @pranavkannan1544
    @pranavkannan1544 7 ปีที่แล้ว +3

    where are the ancestry results

  • @jamesgedny
    @jamesgedny 7 ปีที่แล้ว +4

    SQL Injection is hacking, but a terrible version of hacking. I've been doing it for years.
    If you think SQL injection will help you impress that pretty girl who you work with / go to school with, then you're wrong.

    • @lukefrance9558
      @lukefrance9558 7 ปีที่แล้ว

      Geeky Gamers then what do you use

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +5

      Okay, I'll bite: In your experience, what flavor of website penetration attack discussion does impress the pretty girls?

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +5

      Penetration.

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +3

      heh.

    • @willk1960
      @willk1960 7 ปีที่แล้ว +1

      Geeky Gamers you are completely right, who uses Sql anyways? Today any websites that you would like to hack with sql injection, almost all the time are never worth it.

  • @gaming_pro178
    @gaming_pro178 7 ปีที่แล้ว +2

    Are you going to do XSS next? Oh and love the channel, keep up the great work!

  • @videodrone1515
    @videodrone1515 7 ปีที่แล้ว

    Love your channel so much guys!

  • @merlincnrad5385
    @merlincnrad5385 7 ปีที่แล้ว +22

    ok i'm still early can i get an "Hello World"

    • @gurkanozil
      @gurkanozil 7 ปีที่แล้ว +1

      Hello World!

    • @thewpbard
      @thewpbard 7 ปีที่แล้ว +1

      48656c6c6f20576f726c64

    • @mastertrey4683
      @mastertrey4683 7 ปีที่แล้ว +1

      print ("Hello World")

    • @PrincessNinja007
      @PrincessNinja007 6 ปีที่แล้ว +1

      cout

    • @CWGminer
      @CWGminer 6 ปีที่แล้ว +1

      System.out.println("Hello World");

  • @TommyCallaway
    @TommyCallaway 7 ปีที่แล้ว +20

    I can teach you how to hack the GPS on your iPhone to display coordinates different than where you are actually at, if uh, you want.

    • @TommyCallaway
      @TommyCallaway 7 ปีที่แล้ว +2

      (without jailbreaking or downloading any apps, obviously)

    • @santosmedina4248
      @santosmedina4248 7 ปีที่แล้ว +2

      Tommy Callaway you can use a VPN which constantly changes your IP address (e.g. VPN master)

    • @TommyCallaway
      @TommyCallaway 7 ปีที่แล้ว

      not your IP, I'm talking about the GPS (like what waze, google maps, and other things use)

    • @hellstexian5135
      @hellstexian5135 6 ปีที่แล้ว +7

      Called a GPS spoofer, mock locations. Woah magic.

    • @lokeshreddy3418
      @lokeshreddy3418 6 ปีที่แล้ว

      Install vpn

  • @Fruesgh
    @Fruesgh 7 ปีที่แล้ว

    Been watching for 2 years now, starting with scam school. Keep up the amazing work Brian.

  • @MXCN_El1011
    @MXCN_El1011 7 ปีที่แล้ว

    Great. So I never have to remember a password for any website ever again. Thanks Brian and Jason

  • @nathanielshawtheoverclocke7045
    @nathanielshawtheoverclocke7045 7 ปีที่แล้ว +8

    2:39. If Attempting To Use SQL Injections Is A Felony, Then WHY TEACH THE GENERAL PUBLIC ABOUT IT?? I Learned It In A Computer Science Class. Do you want this channel deleted??? 4:45. The character is actually ' '. My bad. I actually forgot that part, so I threw in what made sense.

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +45

      Welcome to our computer science class, Nathaniel.

    • @wilsoh8816
      @wilsoh8816 7 ปีที่แล้ว

      The Modern Rogue hahahhah

    • @williamkarlbaker
      @williamkarlbaker 7 ปีที่แล้ว

      Good one hahaha

    • @jonasuj
      @jonasuj 7 ปีที่แล้ว +5

      Nathaniel Shaw Why teach people about SQL Injection? So they'll know to protect against it if they ever make a website

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +17

      Oh my dear, sweet Nathaniel. We're going to teach you so many more diabolical things.

  • @ScibbieGames
    @ScibbieGames 7 ปีที่แล้ว +9

    Man this type of hacking is really old and barely works anywhere. But its so much fun to do!

    • @napoleontheafromite
      @napoleontheafromite 7 ปีที่แล้ว +5

      Scibbie / ǝıqqıɔS you'd be surprised how many websites still have SQL vulnerabilities. Most of them aren't really common like Reddit or TH-cam, but they still store people's private information sometimes.

    • @RoadArchie
      @RoadArchie 7 ปีที่แล้ว

      what kind of sites?( ͡° ͜ʖ ͡°)

    • @shary0
      @shary0 7 ปีที่แล้ว

      Of course websites are still vulnerable to SQLi, but the '-- thingy is probably not going to work. More likely you'll have a Time-based blind SQLi or something like that.

    • @napoleontheafromite
      @napoleontheafromite 7 ปีที่แล้ว +2

      ClixSense is a site that recently got hit with SQL injection. It held user's names, usernames, passwords (in cleartext), birthdays, credit card info, and emails. Over 6 and a half million users had their info stolen, and about 2 and half million of that 6.5 had their info publish online.

    • @shary0
      @shary0 7 ปีที่แล้ว

      That's (sadly) not even surprising.

  • @chrisk4706
    @chrisk4706 7 ปีที่แล้ว

    Just had a report due for college and one of parts asked us to give a brief description of SQL Injection Attacks.. thanks for the help haha!

  • @dAnIeL-sy9im
    @dAnIeL-sy9im 7 ปีที่แล้ว +1

    love your videos. keep them coming

  • @coreylarge8639
    @coreylarge8639 7 ปีที่แล้ว +12

    Calling it sequel is triggering me. S Q L

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +21

      Do you need a safe space? Some calming jasmine tea, perhaps?

    • @coreylarge8639
      @coreylarge8639 7 ปีที่แล้ว +5

      Just British things, do you have regular tea on offer? Also your videos are top kek

    • @CWGminer
      @CWGminer 6 ปีที่แล้ว +1

      me too.. I need some of that jasmine tea, Brian.

  • @Thvl3
    @Thvl3 7 ปีที่แล้ว +29

    Why would you show people this? Now thousands of idiots are going to try and hack Roblox or Steam and get arrested. It sure would suck going to prison over a website, wouldn't it?

    • @BrandtHughes
      @BrandtHughes 7 ปีที่แล้ว +47

      Information is never the enemy, especially when this information is already so widely available to anybody looking for it. Same goes with our lockpicking / bump key videos on scam school, letting people know that these vulnerabilities exist helps people who didn't know this was an issue protect against it. Criminals already know how to commit crimes and keeping people in the dark doesn't stop that.

    • @Thvl3
      @Thvl3 7 ปีที่แล้ว +1

      Brandt Hughes That is a great point, but it wouldn't hurt to put more warning towards kids about felonies and punishment for misuse of this information.

    • @BrandtHughes
      @BrandtHughes 7 ปีที่แล้ว +13

      True, I'll add an additional note in the description. It's not much, but it can't hurt to have.

    • @Thvl3
      @Thvl3 7 ปีที่แล้ว

      Brandt Hughes Are you a channel manager?

    • @BrandtHughes
      @BrandtHughes 7 ปีที่แล้ว +2

      Yeah, I'm the editor and do most of the channel management.

  • @june6695
    @june6695 7 ปีที่แล้ว

    awesome that this channel is growing so fast :^) nice vid

  • @TheBeastlyHispanic96
    @TheBeastlyHispanic96 7 ปีที่แล้ว

    And then there was a surge of information hacks on small online business websites lol. Great video guys!

  • @Tag4rce7
    @Tag4rce7 7 ปีที่แล้ว

    hacking is like my favorite subject for you to cover. Thanks for this video

  • @ParkerEdwardsParties
    @ParkerEdwardsParties 7 ปีที่แล้ว

    Oh man. This is the best channel.

  • @kyyowa129
    @kyyowa129 7 ปีที่แล้ว +1

    Mr. Shwood, this show is SO DAMN GOOD.

  • @Chaaos2
    @Chaaos2 7 ปีที่แล้ว +2

    I'm studying programing right now, so cool!

  • @samuelwerstak6392
    @samuelwerstak6392 7 ปีที่แล้ว

    TheModernRogue I love you guys! ive been watching since the beginning. Do a video about hacking with keyloggers and backdoors

  • @GoldenGunner111
    @GoldenGunner111 7 ปีที่แล้ว

    My favorite moment of the week!

  • @nightlyoko626
    @nightlyoko626 7 ปีที่แล้ว

    i love this stuff its so neat to watch and learn new info ♡

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว

      Thanks! I like that it's 'mysterious' to most people.

  • @mig636
    @mig636 7 ปีที่แล้ว

    Your channel is so god damn interesting.I got sucked into watching your videos and i can't stop.......help.

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว

      You'll find no help here!

    • @mig636
      @mig636 7 ปีที่แล้ว

      Jason Murphy I'm serious,i think i have a probl.....wait it's normal to binge watch all the videos on a channel in a row....twice.....right?

  • @dre7084
    @dre7084 7 ปีที่แล้ว +2

    The modern rogue is entertaining and teaches you stuff

  • @ogaje4944
    @ogaje4944 7 ปีที่แล้ว +1

    Great vid man! Keep it up!

  • @mae_online
    @mae_online 7 ปีที่แล้ว

    I am _incredibly_ tempted to try this

  • @Progaros
    @Progaros 7 ปีที่แล้ว

    Please make more of those videos!

  • @wesleygrizzle5369
    @wesleygrizzle5369 7 ปีที่แล้ว

    That is crazy thanks Brian Brushwood

  • @Tristanius11
    @Tristanius11 7 ปีที่แล้ว +2

    As Brian brushed through the wood he found himself lost in it

  • @svapoaquattrocchi7482
    @svapoaquattrocchi7482 7 ปีที่แล้ว +2

    Why this channel hasn't one million subscribe yet?

    • @ModernRogue
      @ModernRogue  7 ปีที่แล้ว +1

      probably because we're less than four months old. (but we'd love it if you helped spread the word!)

    • @svapoaquattrocchi7482
      @svapoaquattrocchi7482 7 ปีที่แล้ว

      The Modern Rogue sure i'll do !

  • @KeljuKkojootti
    @KeljuKkojootti 7 ปีที่แล้ว

    I just love this channel :3

  • @rcksnxc361
    @rcksnxc361 7 ปีที่แล้ว

    Im hooked to this channel

  • @WashingMachineKiller
    @WashingMachineKiller 7 ปีที่แล้ว

    I absolutely LOVE the modern rouge!!

  • @mrslendygaming6352
    @mrslendygaming6352 7 ปีที่แล้ว +13

    Hey I'm the guy who was the employee at heb in the Santa hat on Christmas Eve that said hi.

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +15

      Hey! It was great meeting you. Thanks for saying 'hi!'

    • @superyoshi7777
      @superyoshi7777 7 ปีที่แล้ว +2

      Technically it's illegal, but would I be able to retrieve my hacked steam account through this?

    • @sebi821
      @sebi821 7 ปีที่แล้ว +2

      Probably not. Steam security measurements are damn good... Also it's illegal and you could get into loads of trouble attempting something like that with a huge company as a target. So dont.

    • @TheStrangerous
      @TheStrangerous 7 ปีที่แล้ว +5

      Do NOT attempt that. Even if it's your account.

  • @andrewbenge2040
    @andrewbenge2040 7 ปีที่แล้ว

    I'm gonna wind up on some kind of watchlist, just from watching this channel.

  • @KevinLikesBananas
    @KevinLikesBananas 7 ปีที่แล้ว

    this is such a cool episode

  • @BigerBoy
    @BigerBoy 7 ปีที่แล้ว

    Guys you are awesome this is my favorite channel and this is my type of videos (programming) can you do something related with kali Linux.

    • @BigerBoy
      @BigerBoy 7 ปีที่แล้ว

      +slim Shady yep me neither

  • @overloadcomputers2278
    @overloadcomputers2278 7 ปีที่แล้ว

    Something that the Modern Rogue a) Doesn't have experience with and b) Is afraid of messing with; We need more of this.

  • @jamcastillo01
    @jamcastillo01 7 ปีที่แล้ว

    so a random question, but are they making another one of the logos at the end everytime they make a new video? because that would be kinda cool

  • @jakeabel2548
    @jakeabel2548 7 ปีที่แล้ว

    Good episode. As someone who just finished setting up a bunch of prepared statements. This video makes it seem over complicated. It is like typing an extra few lines of code. The real problems with securing this stuff is when you need to find redo some production code. The method before prepared statements was/is comment out ' which you just replace all ' with \' and this means this tick is not code. You need to put that into the program and do that before you send the data to the sql server. Bunch of information for you all in case you wanted to know.

  • @nathanwilliams3837
    @nathanwilliams3837 7 ปีที่แล้ว

    glad to see Nick Oliveri is staying busy

  • @newvision1665
    @newvision1665 7 ปีที่แล้ว

    Do you have to download anything for this, btw amazing videos!

  • @kaiyomoon
    @kaiyomoon 7 ปีที่แล้ว

    Sees sql in the title, expects a sequel pun.
    Not disappointed