SQL Injection - CompTIA Security+ SY0-701 - 2.3 — Transcript
Full transcript
- 0:02A code injection attack is a very common
- 0:04application attack where the attacker
- 0:06will put their own code into information
- 0:09that is input into the application. This
- 0:11obviously is an attack that should not
- 0:13be allowed in the application, but the
- 0:15application developers have to put
- 0:17checks into their code to prevent any
- 0:19type of unnecessary or unwanted
- 0:22application data being injected during
- 0:24the normal input into the app. And
- 0:27you'll hear about many different kinds
- 0:29of code injections. There is HTML code
- 0:31injection, SQL injections, XML
- 0:34injections, and others.
- 0:36Let's look at one specific type of code
- 0:38injection. This is the SQL injection.
- 0:41SQL stands for structured query language
- 0:43and it's probably the most popular way
- 0:45to have an application interact with a
- 0:47database. The way your application is
- 0:50supposed to work is that it will take
- 0:51information that you're inputting into
- 0:53the application and use that information
- 0:55as queries into the database. A SQL
- 0:58injection or SQLI allows an attacker to
- 1:01put their own requests into this query
- 1:04that's being made to the database.
- 1:06Obviously, the application should not be
- 1:08allowing this, but if an application
- 1:10doesn't have the proper checks, then you
- 1:11can send anything you'd like to the
- 1:13database. This is also often not a
- 1:16difficult vulnerability to exploit. You
- 1:18can do this within the browser that's
- 1:20being used as the front end to the
- 1:21application and simply inject your data
- 1:24into the input fields that are already
- 1:26in that application.
- 1:28If you were to look behind the scenes at
- 1:30the code that's communicating between
- 1:32your browser and the web server and
- 1:34database server, you would see something
- 1:36like this. This is website code that
- 1:38does a select asterisk from users where
- 1:42name equals and then everything in red
- 1:44is added by the application. In this
- 1:47particular query, you're asking the
- 1:49database to select all information where
- 1:52a particular username equals a username
- 1:55that you're putting into the app. So, if
- 1:57you're using an application where you're
- 1:59putting in a name to search, such as the
- 2:01name professor, the code that's sent to
- 2:03the database says, select everything
- 2:06from users where name equals professor.
- 2:09Now, normally that would be the end of
- 2:11the transaction, but if this application
- 2:14is vulnerable to code injection, we can
- 2:16add our own SQL code into this query.
- 2:20So, instead of just asking for a
- 2:21username, we would select asterisk from
- 2:24users where name equals professor or 1 =
- 2:291. This is a common form to be able to
- 2:32ask for everything that may be in the
- 2:35database because obviously 1 does equal
- 2:381, and if you ever see any code being
- 2:40sent to a database where the request is
- 2:43asking if 1 = 1, it's very likely that
- 2:46you've run into a SQL injection.
- 2:49You can also see how easy it is to
- 2:50exploit this vulnerability. All you have
- 2:52to do is add additional code into the
- 2:55input line of the application. There's
- 2:57no additional software that has to be
- 2:59written. You don't have to somehow make
- 3:01a user click a piece of information. All
- 3:03you have to do is add additional code
- 3:05into the app. This type of exploit can
- 3:08also provide you with a great deal of
- 3:10control of the data in that database.
- 3:13Because you're circumventing the
- 3:14security of this database, you
- 3:16effectively now have complete control to
- 3:18the data inside. You can view everything
- 3:21that's in the database or delete
- 3:22everything that's in the database or
- 3:24simply make changes or bring the
- 3:26database down so that nobody can access
- 3:28the data.
- 3:29Let's look at an example of SQL
- 3:31injection. I'm using an application that
- 3:34has been specifically written to be
- 3:36vulnerable. It's part of a series of
- 3:38applications called WebGoat, and you can
- 3:40find it at webgoat.org.
- 3:42In this case, we have two pieces of
- 3:44information we're going to add to the
- 3:46application, an employee name, which is
- 3:48Smith, and a transaction authentication
- 3:50number, which is something like a
- 3:52password, and we're going to add that
- 3:54into that field for 3SL99A.
- 3:58So, if you were normally logging in with
- 4:00your name and your password, you can
- 4:02click get department, and it shows you
- 4:04the department information for that
- 4:06particular query. Notice that this query
- 4:09is limited to the name Smith and to this
- 4:11specific transaction authentication
- 4:14number.
- 4:15Now, let's use SQL injection to view all
- 4:17of the information that's inside of the
- 4:19database. We'll use the same username
- 4:22and the same transaction authentication
- 4:24number, but I'm going to include
- 4:26additional injected code into this
- 4:28field. We'll put an apostrophe or
- 4:31apostrophe one {apostrophe} =
- 4:34{apostrophe} one. So, we're adding in
- 4:36that additional code that says, "Look
- 4:38for everything where the transaction
- 4:40authentication number is 3SL99A
- 4:43or any place where one happens to equal
- 4:46one." And since one does equal one, when
- 4:50we get department, it provides us with
- 4:52everything that's in the database, and
- 4:54we effectively now have complete control
- 4:57of all of this data.
About this transcript
This page contains the full transcript of SQL Injection - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 829 words across 129 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.