YouTube2Text

SQL Injection - CompTIA Security+ SY0-701 - 2.3 — Transcript

by Professor Messer · 829 words · 129 segments · language en · Watch on YouTube

Full transcript

  1. 0:02A code injection attack is a very common
  2. 0:04application attack where the attacker
  3. 0:06will put their own code into information
  4. 0:09that is input into the application. This
  5. 0:11obviously is an attack that should not
  6. 0:13be allowed in the application, but the
  7. 0:15application developers have to put
  8. 0:17checks into their code to prevent any
  9. 0:19type of unnecessary or unwanted
  10. 0:22application data being injected during
  11. 0:24the normal input into the app. And
  12. 0:27you'll hear about many different kinds
  13. 0:29of code injections. There is HTML code
  14. 0:31injection, SQL injections, XML
  15. 0:34injections, and others.
  16. 0:36Let's look at one specific type of code
  17. 0:38injection. This is the SQL injection.
  18. 0:41SQL stands for structured query language
  19. 0:43and it's probably the most popular way
  20. 0:45to have an application interact with a
  21. 0:47database. The way your application is
  22. 0:50supposed to work is that it will take
  23. 0:51information that you're inputting into
  24. 0:53the application and use that information
  25. 0:55as queries into the database. A SQL
  26. 0:58injection or SQLI allows an attacker to
  27. 1:01put their own requests into this query
  28. 1:04that's being made to the database.
  29. 1:06Obviously, the application should not be
  30. 1:08allowing this, but if an application
  31. 1:10doesn't have the proper checks, then you
  32. 1:11can send anything you'd like to the
  33. 1:13database. This is also often not a
  34. 1:16difficult vulnerability to exploit. You
  35. 1:18can do this within the browser that's
  36. 1:20being used as the front end to the
  37. 1:21application and simply inject your data
  38. 1:24into the input fields that are already
  39. 1:26in that application.
  40. 1:28If you were to look behind the scenes at
  41. 1:30the code that's communicating between
  42. 1:32your browser and the web server and
  43. 1:34database server, you would see something
  44. 1:36like this. This is website code that
  45. 1:38does a select asterisk from users where
  46. 1:42name equals and then everything in red
  47. 1:44is added by the application. In this
  48. 1:47particular query, you're asking the
  49. 1:49database to select all information where
  50. 1:52a particular username equals a username
  51. 1:55that you're putting into the app. So, if
  52. 1:57you're using an application where you're
  53. 1:59putting in a name to search, such as the
  54. 2:01name professor, the code that's sent to
  55. 2:03the database says, select everything
  56. 2:06from users where name equals professor.
  57. 2:09Now, normally that would be the end of
  58. 2:11the transaction, but if this application
  59. 2:14is vulnerable to code injection, we can
  60. 2:16add our own SQL code into this query.
  61. 2:20So, instead of just asking for a
  62. 2:21username, we would select asterisk from
  63. 2:24users where name equals professor or 1 =
  64. 2:291. This is a common form to be able to
  65. 2:32ask for everything that may be in the
  66. 2:35database because obviously 1 does equal
  67. 2:381, and if you ever see any code being
  68. 2:40sent to a database where the request is
  69. 2:43asking if 1 = 1, it's very likely that
  70. 2:46you've run into a SQL injection.
  71. 2:49You can also see how easy it is to
  72. 2:50exploit this vulnerability. All you have
  73. 2:52to do is add additional code into the
  74. 2:55input line of the application. There's
  75. 2:57no additional software that has to be
  76. 2:59written. You don't have to somehow make
  77. 3:01a user click a piece of information. All
  78. 3:03you have to do is add additional code
  79. 3:05into the app. This type of exploit can
  80. 3:08also provide you with a great deal of
  81. 3:10control of the data in that database.
  82. 3:13Because you're circumventing the
  83. 3:14security of this database, you
  84. 3:16effectively now have complete control to
  85. 3:18the data inside. You can view everything
  86. 3:21that's in the database or delete
  87. 3:22everything that's in the database or
  88. 3:24simply make changes or bring the
  89. 3:26database down so that nobody can access
  90. 3:28the data.
  91. 3:29Let's look at an example of SQL
  92. 3:31injection. I'm using an application that
  93. 3:34has been specifically written to be
  94. 3:36vulnerable. It's part of a series of
  95. 3:38applications called WebGoat, and you can
  96. 3:40find it at webgoat.org.
  97. 3:42In this case, we have two pieces of
  98. 3:44information we're going to add to the
  99. 3:46application, an employee name, which is
  100. 3:48Smith, and a transaction authentication
  101. 3:50number, which is something like a
  102. 3:52password, and we're going to add that
  103. 3:54into that field for 3SL99A.
  104. 3:58So, if you were normally logging in with
  105. 4:00your name and your password, you can
  106. 4:02click get department, and it shows you
  107. 4:04the department information for that
  108. 4:06particular query. Notice that this query
  109. 4:09is limited to the name Smith and to this
  110. 4:11specific transaction authentication
  111. 4:14number.
  112. 4:15Now, let's use SQL injection to view all
  113. 4:17of the information that's inside of the
  114. 4:19database. We'll use the same username
  115. 4:22and the same transaction authentication
  116. 4:24number, but I'm going to include
  117. 4:26additional injected code into this
  118. 4:28field. We'll put an apostrophe or
  119. 4:31apostrophe one {apostrophe} =
  120. 4:34{apostrophe} one. So, we're adding in
  121. 4:36that additional code that says, "Look
  122. 4:38for everything where the transaction
  123. 4:40authentication number is 3SL99A
  124. 4:43or any place where one happens to equal
  125. 4:46one." And since one does equal one, when
  126. 4:50we get department, it provides us with
  127. 4:52everything that's in the database, and
  128. 4:54we effectively now have complete control
  129. 4:57of all of this data.

About this transcript

This page contains the full transcript of SQL Injection - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 829 words across 129 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.