Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

SQL Injection Tutorial - Union and Blind Attacks in Gin and Juice Shop

CryptoCat via YouTube

Overview

Learn SQL injection techniques through a hands-on tutorial video exploring both Union and Blind attacks against Portswigger's intentionally vulnerable Gin and Juice shop web application. Master essential penetration testing skills including database enumeration, column identification, syntax manipulation, and automated extraction using Burp Suite. Progress through practical demonstrations of exploiting high to low severity vulnerabilities, working with base64-encoded JSON cookies, and attempting SQLMap automation. Designed for aspiring bug bounty hunters, security researchers, penetration testers and CTF players, this comprehensive walkthrough covers fundamental concepts like determining column datatypes, extracting sensitive data, and leveraging both manual and automated testing approaches. Follow along with detailed chapters breaking down each attack phase while learning industry-standard tools and methodologies used in real-world web application security testing.

Syllabus

Intro
Recap
Redeploy live audit scan
Known vulnerabilities endpoint
Review scan results
Recreate the vulnerability SQLi
Useful SQLi resources
Union vs Blind injection
Finding the correct syntax comments
Identify number of columns order by
Determine column datatypes
Enumerate databases union attack
Enumerate tables
Enumerate columns
Extract username and password
Blind SQLi attack
Determine database name length
Extract database name substring
Automate extraction with burp intruder
Issue #2: SQL in base64-encoded JSON cookie
Fail to automate with burp macros / session handling
SQLMap burp extension bApp
Test SQLMap CLI fails to get DB type/version
Conclusion

Taught by

CryptoCat

Reviews

Start your review of SQL Injection Tutorial - Union and Blind Attacks in Gin and Juice Shop

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.