Advanced SQL Injection Tutorial

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 พ.ย. 2024

ความคิดเห็น • 218

  • @presenzemisteriose
    @presenzemisteriose 3 ปีที่แล้ว +36

    Hi, I bought the course, can I write to you privately for any questions? thanks you are the best

    • @LoiLiangYang
      @LoiLiangYang  3 ปีที่แล้ว +18

      Yes. Feel free to post your questions in Udemy and our team will get right back to you! If you're a TH-cam member of this channel, likewise too!

    • @presenzemisteriose
      @presenzemisteriose 3 ปีที่แล้ว +6

      @@LoiLiangYang Thank you very much, I also sent you a message on udemy, I'm watching videos on payload on Android but I had problems in practice I write to you thanks again, and I must say you teach well good ☺️

    • @presenzemisteriose
      @presenzemisteriose 3 ปีที่แล้ว +1

      how do i port forward for with smartphone connection

    • @rohimpiana711
      @rohimpiana711 3 ปีที่แล้ว +2

      How can I become a youtube member ?

    • @trickshot8653
      @trickshot8653 3 ปีที่แล้ว

      @@LoiLiangYang could you please make a video for hacking database using sql injection . All techniques possible

  • @yunus-gedik
    @yunus-gedik 3 ปีที่แล้ว +5

    Loi is the best security instructor on TH-cam .
    Thanks from 🇨🇵

  • @LoiLiangYang
    @LoiLiangYang  3 ปีที่แล้ว +15

    Additionally, you look for vulnerabilities in the input fields by throwing in payloads to get error. This is important because once you discover the vulnerability, the advanced segment of using UNION to pull out more data comes in to play.

    • @swarnabhargavi5680
      @swarnabhargavi5680 2 ปีที่แล้ว

      Plz do SQL injection video of Login Page having Captcha. All videos on internet shows only on Login page having Username and Password

  • @shubhankarparanjape7693
    @shubhankarparanjape7693 3 ปีที่แล้ว +24

    I can’t express how underrated your channel is considering how amazing & valuable content you are providing. Keep it up man, major hats off to you! Lots of love from India 🇮🇳

  • @chillydoog
    @chillydoog 3 ปีที่แล้ว +4

    Your voice is so soothing and smooth. Handsome, smart, effective.

  • @thundermc4480
    @thundermc4480 3 ปีที่แล้ว +1

    You are a life changer for me. I always wanted to do ethical hacking. And now i work on a univeruity

  • @X-secular
    @X-secular 3 ปีที่แล้ว +40

    Love ❤️ from India 🇮🇳

    • @john_vinith
      @john_vinith 3 ปีที่แล้ว +2

      🇮🇳

    • @b07x
      @b07x 3 ปีที่แล้ว +4

      Love ❤️ from Turkey 🇹🇷

    • @secretmystery8305
      @secretmystery8305 3 ปีที่แล้ว +3

      1st & 2nd cmt from BD but pinned cmt fro. in. Really this is heart Broken think.😔🙄😒🤔

    • @X-secular
      @X-secular 3 ปีที่แล้ว +2

      @@secretmystery8305 don't worry bro.... Good luck for next time....

    • @secretmystery8305
      @secretmystery8305 3 ปีที่แล้ว +1

      @@X-secular Thank You So Much. :)

  • @technologymakeeasy
    @technologymakeeasy 3 ปีที่แล้ว

    Thanks my teacher, i have hijack a website using your way. And now i have 1000% full access -

  • @arshadakl
    @arshadakl 3 ปีที่แล้ว +13

    make a video about SQL injection filter bypassing

  • @ewaat
    @ewaat 3 ปีที่แล้ว +2

    I just can't wait for other videos, much love from Kenya

  • @Alain9-1
    @Alain9-1 3 ปีที่แล้ว +2

    Underrated channel

  • @aiziz1658
    @aiziz1658 3 ปีที่แล้ว +3

    this is great man, exactly same as what i leran from school

  • @_Thomas_Shelby_
    @_Thomas_Shelby_ 3 ปีที่แล้ว

    In pandemic time ur spending ur precious time to teach 4r us sir,by cing ur cls.. in udemy we have learnt Sir tq sir.

  • @secretmystery8305
    @secretmystery8305 3 ปีที่แล้ว +4

    Love From Bangladesh :)

  • @varunfoodvlog9215
    @varunfoodvlog9215 3 ปีที่แล้ว

    hey u are a osm osm hacker wow i am fast time see your channel from india and u grow more

  • @japhetmnyeta1076
    @japhetmnyeta1076 2 หลายเดือนก่อน

    Your good brother,your tutorials are understandable

  • @marcush3ll673
    @marcush3ll673 3 ปีที่แล้ว +2

    Love from INDIA ❤️

  • @john_vinith
    @john_vinith 3 ปีที่แล้ว

    Good channels are mostly under rated... Very useful content.... yesterday i was looking for this... 🖤🖤🖤

  • @Nihillius
    @Nihillius 3 ปีที่แล้ว +1

    you are The best by the way i am You Fan i saw every videos

  • @Moderator.
    @Moderator. 3 ปีที่แล้ว +7

    But what about the Salt into Hashing.. Almost everyone does it now... A salted hash can't be reversed.

  • @iuseyahoo
    @iuseyahoo 3 ปีที่แล้ว

    Loi I learn more from you in a 5 minute video rather than someone else’s 15 min video

  • @sharmaabhijit5831
    @sharmaabhijit5831 3 ปีที่แล้ว +1

    Lot of Respect to your Work Sir.
    Like a consistent student who regularly watches your video but I have a query from where u get sql payload can u make a video on that how to find or check payload available

  • @Zero5309
    @Zero5309 3 ปีที่แล้ว +6

    Really well explained! What I would like to have are more realistic attacks. I mean are there actually still up to date webapps with that kind of vulnerabilities? What would a SQL injection look like in realistic scenario? Still a great video :)

    • @roniwinchester8351
      @roniwinchester8351 3 ปีที่แล้ว

      understanding means "Etichal Hacking" they never attack other people in real life. it's all about demonstrated

    • @Zero5309
      @Zero5309 3 ปีที่แล้ว

      @@roniwinchester8351 yes but the video title is "Advanced SQL Injection Tutorial". What he showed is the least level of diffidulty possible

    • @roniwinchester8351
      @roniwinchester8351 3 ปีที่แล้ว

      @@Zero5309 then learn in google, you can't force anyone to teach you how to hack in real world.

    • @Zero5309
      @Zero5309 3 ปีที่แล้ว

      @@roniwinchester8351 ??? What are you even talking about. That's what this channel is all about. He's already showing how to hack. If the title says advanced I dont want to see most basic stuff.

    • @russnemet1158
      @russnemet1158 3 ปีที่แล้ว +1

      If you want to see real SQL xss attacks check for bug bounty videos. Or videos of how the winners of a bug bounty won the bounty.

  • @freelancersharif2051
    @freelancersharif2051 3 ปีที่แล้ว

    wow, wonderful, we want more tutorials. thank you so much for sharing this valuable hacking method. take love from Bangladesh

  • @gostxost
    @gostxost 4 หลายเดือนก่อน

    Mr Loi, you used the SQL injection attack with a completely different method. I thought you would run code like or '1=1# or or 8888=8888--. Then you will find the tables and columns on the site. I thought you would capture it.
    I can use sqlmap, but I cannot do it manually. Because I didn't fully understand how to do it.

  • @gamekanstudios
    @gamekanstudios 3 ปีที่แล้ว +2

    Thanks mr loi for teaching me

  • @devanshkanda9618
    @devanshkanda9618 3 ปีที่แล้ว +1

    Thank you sir ❤️ love from india ❤️❤️

  • @aniketjoshi6286
    @aniketjoshi6286 3 ปีที่แล้ว +1

    Love ❤️ from India 🇮🇳
    Can i get a heart ??

  • @NicatZadeh
    @NicatZadeh ปีที่แล้ว

    Hello, some cyber security expert told me that real site is not actually attacked in this way. Do you think this is true? Should I try your suggested method if I want to attack any site? Please reply. I want to ask one more thing. What is a sql map? What is the difference between sql map and this specified method? How can we do this?

  • @rafin5651
    @rafin5651 3 ปีที่แล้ว +1

    Love from Bangladesh 🇧🇩❤️😊

    • @mukto2004
      @mukto2004 3 ปีที่แล้ว +1

      hacker from bd i see

    • @b07x
      @b07x 3 ปีที่แล้ว

      @@mukto2004 🇹🇷🇧🇩🇩🇿🇮🇳🇵🇰🇨🇳🇷🇺🇺🇲🇬🇧 Most of the hackers are from these countries.

    • @mukto2004
      @mukto2004 3 ปีที่แล้ว

      @@b07x pak ? How ?

  • @a-71ameymuke84
    @a-71ameymuke84 3 ปีที่แล้ว

    You are great teacher sir I have learned many things from you Much love and support to you❤❤💯

  • @tassiblezilundu7602
    @tassiblezilundu7602 3 ปีที่แล้ว

    Let me confess that you're the best Loo Liang.... I want to make just one request.... make a video that would cover how to locate a phone number currently working and combined with one which is not currently working thanks

  • @nosignal5735
    @nosignal5735 3 ปีที่แล้ว +1

    If I may know, does cyber security pay well? Average per year? And which one makes more money, cyber sec or game development company? I'm interested in both fields but I don't know which one to choose....

    • @mrintel10
      @mrintel10 2 ปีที่แล้ว

      I'd say cyber security but with game development it varies on your position as with cyber security

  • @kodjovinicolasanatoh4521
    @kodjovinicolasanatoh4521 3 ปีที่แล้ว +2

    Please I need a video on how to access friends contact list by Link. Or by generating a payload.
    Thanks

  • @mr.hackme7435
    @mr.hackme7435 3 ปีที่แล้ว +1

    Such amazing Hacker ❤️

  • @Real_delron
    @Real_delron 3 ปีที่แล้ว +1

    Thanks been waiting for this..❤️

  • @wintorez6649
    @wintorez6649 3 ปีที่แล้ว +1

    Thank you sir for making this video 🇮🇳🇮🇳🇮🇳🇮🇳🇮🇳

  • @mralien0047
    @mralien0047 3 ปีที่แล้ว +1

    Thnq my teacher, you're the best of the best

  • @aFynoX
    @aFynoX 3 ปีที่แล้ว +1

    Great content😎😎😎 Sir keep it up 👍

  • @sohankhan4042
    @sohankhan4042 3 ปีที่แล้ว +8

    Love from Bangladesh 🇧🇩

    • @secretmystery8305
      @secretmystery8305 3 ปีที่แล้ว +3

      Nice. look 1st 2 cmt from bangladesh. I think all Bangli Love Hawking Like Me :)

    • @rafin5651
      @rafin5651 3 ปีที่แล้ว

      @@secretmystery8305 I am also come from Bangladesh 🙂..

    • @secretmystery8305
      @secretmystery8305 3 ปีที่แล้ว

      @@rafin5651 nice :)

    • @rafin5651
      @rafin5651 3 ปีที่แล้ว +1

      @@secretmystery8305 yeah ...😁

    • @secretmystery8305
      @secretmystery8305 3 ปีที่แล้ว

      @@rafin5651 lets hack uuuuuu 😀😅

  • @xcypher
    @xcypher 3 ปีที่แล้ว +1

    Love from indonesian 🇮🇩 :)

  • @nepaliredteam1713
    @nepaliredteam1713 3 ปีที่แล้ว

    Love 💞 from Nepal 🇳🇵

  • @LoiLiangYang
    @LoiLiangYang  3 ปีที่แล้ว

    What do you think /**/ is for?

    • @d3vast8r
      @d3vast8r 3 ปีที่แล้ว

      Commenting things out..

  • @abczwq8364
    @abczwq8364 ปีที่แล้ว

    and how did you discovered those were valid fields on the user table? ..how did you discovered the table name? how did you discovered the type of database ? ... if this is an advance tutorial you should explain how did you came up with the payloads , not just to do a copy paste

  • @b391i
    @b391i 3 ปีที่แล้ว +2

    KEEP GOING MY FRIEND 😎👍

  • @alexxxk
    @alexxxk 3 ปีที่แล้ว

    This guy teach so good !!!

  • @st1llbleed1ng
    @st1llbleed1ng ปีที่แล้ว

    Man your first union select query, was it fluke or actually there were 9 columns in users table? Also can you explain why you used /**/?
    Finally all the columns except the last one in the users table were string type?

  • @jamesgray4037
    @jamesgray4037 2 ปีที่แล้ว

    Dude my freind u are a legend

  • @nazarshved7504
    @nazarshved7504 3 ปีที่แล้ว +1

    How would you know the exact name of a table and it's columns?

  • @spacifiasome2229
    @spacifiasome2229 3 ปีที่แล้ว

    Love from sri lanka 🇱🇰🇱🇰🇱🇰
    By the way how did you run samsung android framework on windows in previous videos

  • @sahilrajput3063
    @sahilrajput3063 3 ปีที่แล้ว +1

    make a video on API

  • @wealthyDev
    @wealthyDev 3 ปีที่แล้ว

    I just understood why my moms movies site account, one year ago got hacked😂 SQL Injection is way too powerfull :)

  • @TAIRASION
    @TAIRASION ปีที่แล้ว

    My response can be regarded as just as shot in the dark bro as I am still a no-eye deer, hahaha.

  • @_heffen
    @_heffen ปีที่แล้ว

    woooooh amazinf simple tutorial

  • @AnthonyMcqueen1987
    @AnthonyMcqueen1987 3 ปีที่แล้ว

    Wow i was inpressed SQL Injection should not be as difficult its all on what happens on the server.

  • @hackwithjack4816
    @hackwithjack4816 3 ปีที่แล้ว +1

    Thanks alot mr.sir

  • @timotiuslartutul3974
    @timotiuslartutul3974 3 ปีที่แล้ว

    Very educational. Thank you for create this Chanel. but honestly, I'm still not very good at understanding English so please help me to provide Indonesian subtitle. i'm from Indonesian btw.🙏🙏🙏🙏🙏

  • @marcush3ll673
    @marcush3ll673 3 ปีที่แล้ว +1

    You're great sir !

  • @chaitu007
    @chaitu007 3 ปีที่แล้ว

    Keep upload more videos related to sql

  • @soumkadi2776
    @soumkadi2776 3 ปีที่แล้ว

    In the payload does I can Write just
    SELECT * FROM users ??

  • @jackpersonal9657
    @jackpersonal9657 3 ปีที่แล้ว +1

    Is this advanced? Can you make an even more advanced one where you talk about information_schema etc and find the tables manually without being given the stuff like in this video, or bomb shells or writing or reading mitigation

  • @arshadakl
    @arshadakl 3 ปีที่แล้ว +1

    How can monitor mobile traffic using wireshark

  • @aliibrahim5479
    @aliibrahim5479 3 ปีที่แล้ว

    This depends on the database right? I mean would the query be the same if the website was using a different database and if not then how would you know what query to use? do you just have to keep trying ?

    • @bakedtomatohh807
      @bakedtomatohh807 3 ปีที่แล้ว +2

      Check the whatweb data of the website. It will show in the result which database language has been used.

    • @aliibrahim5479
      @aliibrahim5479 3 ปีที่แล้ว

      @@bakedtomatohh807 thank u

  • @irinitsouri4074
    @irinitsouri4074 ปีที่แล้ว

    Love that 9:07

  • @akashjain3100
    @akashjain3100 3 ปีที่แล้ว

    Bro can u plz tell how many langauge we have to know to become network pentester ?

  • @smahidhar516
    @smahidhar516 3 ปีที่แล้ว +1

    Bro where i can learn ethical hacking from basics to advance

  • @ChandupaHerath
    @ChandupaHerath ปีที่แล้ว

    I think for hashing MD5 algorithm is not the industry standard.

  • @s.aravindh6227
    @s.aravindh6227 3 ปีที่แล้ว +2

    Nice video 👍👍👍

  • @sudipdiyasi9647
    @sudipdiyasi9647 ปีที่แล้ว

    Please make a video on sql injection shell upload using sqlmap.

  • @GooDog2906
    @GooDog2906 8 หลายเดือนก่อน

    your program languague to write this lab ? PHP and MYSQL

  • @isakadzemusicc
    @isakadzemusicc 2 ปีที่แล้ว

    how to use this teqnique when there is no searchbar and there is only login and password fill forms?

  • @muhammadnaeef4731
    @muhammadnaeef4731 3 ปีที่แล้ว +1

    frist like i love you fram syria 🇸🇾

  • @forprogramming39
    @forprogramming39 3 ปีที่แล้ว

    thank you very much
    you profstional strong

  • @williamgomez6087
    @williamgomez6087 3 ปีที่แล้ว

    Master of masters!

  • @Unknown-si8uu
    @Unknown-si8uu 3 ปีที่แล้ว +2

    Bro wr are u from

  • @rukshanaaly7794
    @rukshanaaly7794 2 ปีที่แล้ว

    so this is union based sql injection sir ?

  • @ethicmedia3870
    @ethicmedia3870 3 ปีที่แล้ว

    wordpress hacking tutorial plzzz

  • @prathap304
    @prathap304 3 ปีที่แล้ว

    Iam student from India.
    There are no major degree in cybersecurity , where I live.
    Can I take Information technology or Computer Science degree to get started in cybersecurity field??
    Can you give me a suggestion to get started in the field.
    I was more passionate about it...

  • @akinwalefemi8728
    @akinwalefemi8728 3 ปีที่แล้ว

    you are ther boss. thx

  • @Mamuli_28
    @Mamuli_28 2 ปีที่แล้ว

    sir pls make sqlmap videos 🙏🏻 thanku

  • @oaychicolofi4845
    @oaychicolofi4845 2 ปีที่แล้ว

    how can i come up with that union select, kinda weird

  • @yahyabammi5622
    @yahyabammi5622 3 ปีที่แล้ว +1

    good tutorial

  • @SathishkumarM
    @SathishkumarM 3 ปีที่แล้ว +1

    Great video. Could you please tell me how to test SQLi for below API call? This endpoint support GET, POST and DELETE method also.
    GET /api/v1/user/profile/123.
    If there is any article or video on finding SQLi, XSS, CSRF on API's, please share

    • @br33z49
      @br33z49 3 ปีที่แล้ว

      Check for improper access control, You might find some juice

  • @trickshot8653
    @trickshot8653 3 ปีที่แล้ว

    if it doesnt work on a website then other sql payloads wont work as well?

  • @andreasclaudius9076
    @andreasclaudius9076 ปีที่แล้ว

    if i don t have this rest/products ?

  • @TalsonHacks
    @TalsonHacks 3 ปีที่แล้ว +1

    Quantitys

  • @ramkanwar9697
    @ramkanwar9697 3 ปีที่แล้ว +3

    Awesome 🔥🔥🔥🔥🔥

  • @Finnriderlife
    @Finnriderlife 3 ปีที่แล้ว

    Can you do a Lesson on Beef / Ngrok / Portforwarding on WAN. Just dont get it working..

  • @ianmoraga37
    @ianmoraga37 3 ปีที่แล้ว +1

    Next: advance server side request forgery

  • @GlobusZZ
    @GlobusZZ 3 ปีที่แล้ว

    Loi how i can get owasp juice shop on my kali ? Am i need to download ova or iso image with running juice shop ?

  • @anydayanymoment6159
    @anydayanymoment6159 3 ปีที่แล้ว +1

    Does this work on TEST websites or for real ones? I know few shitty websites and would love to hack it, ?

  • @reahnascent8650
    @reahnascent8650 2 ปีที่แล้ว

    But all this attack doesn’t work on live website, why???

  • @shaikgalib8168
    @shaikgalib8168 3 ปีที่แล้ว

    Thanks you

  • @SecurityTalent
    @SecurityTalent 3 ปีที่แล้ว

    Thanks

  • @gladio2029
    @gladio2029 3 ปีที่แล้ว +1

    Open The door,FBI

  • @fmbyts1256
    @fmbyts1256 2 ปีที่แล้ว

    what to do if domain is Locked?

  • @savagesavage6923
    @savagesavage6923 2 ปีที่แล้ว

    Great thanks!

  • @ITZUMYK
    @ITZUMYK 3 ปีที่แล้ว +1

    Awesome video!

  • @DushmanthaKriyaanvithadk0
    @DushmanthaKriyaanvithadk0 3 ปีที่แล้ว

    Thank u 😍

  • @abdulaahikulane3640
    @abdulaahikulane3640 3 ปีที่แล้ว

    you are amazing