Made by: Nguyễn Thắng Lợi from HCMUTE ISC
[Link]
SQL Injection
GIÁO TRÌNH
1. Học và làm các bài lab của PortSwigger tại link sau
[Link]
2. Học thêm từ nguồn Cookie Hân Hoan
Tất Tần Tật Về SQL Injection Cho Người Mới – Không Cần Kiến Thức Chuyên…
Giải Thích Blind SQL Injection Dễ Hiểu Cho Người Mới Bắt Đầu
LUYỆN TẬP
1. [Link]
2. [Link]
3. [Link]
4. [Link]
5. [Link]
6. [Link]
7. [Link]
8. [Link]
9. [Link]
10. [Link]
11. [Link]
12. [Link]
13. [Link]
14. [Link]
Made by: Nguyễn Thắng Lợi from HCMUTE ISC
[Link]
15. [Link]
16. [Link]
17. [Link]
18. [Link]
19. [Link]
20. [Link]
21. [Link]
THAM KHẢO
1. Blogs & Real Cases
1. SQL injection in largest Electricity Board of Sri Lanka | by coffinxp | InfoSec Write-ups
2. How I bypassed Akamai WAF and exploited SQL Injection
3. Introducing: XOR-Based SQL Injection
4. My Bug Bounty Journey and My First Critical Bug — Time Based Blind SQL Injection
5. Turning Blind Error Based SQL Injection into Exploitable Boolean One | by Ozgur Alp
6. Error-Based SQL Injection on a WordPress website and extract more than 150k user
details | by Ynoof Alassiri
7. Super Blind SQL Injection- $20000 bounty | Thousands of targets still vulnerable | by
priyanshu shakya | Medium
8. How to find Blind SQL injection on uri path on Bug bounty programs
9. How to find Blind SQL injection on uri path on Bug bounty programs
10. 4 Ways To Use SQLMAP Effectively For SQL Injection! | Bug Bounty | 2024
Made by: Nguyễn Thắng Lợi from HCMUTE ISC
[Link]
11. [Link] 4500$
12. [Link] 4500$
13. [Link] 4134$
14. [Link] 2000$ CVE-2017-0914
15. Acronis | Report #1224660 - bypass sql injection #1109311 | HackerOne
16. U.S. Dept Of Defense | Report #2597543 - Blind Sql Injection in [Link] |
HackerOne
17. HackerOne | Report #435066 - SQL injection in GraphQL endpoint through
embedded_submission_form_uuid parameter
2. Tools & Payloads
GitHub - swisskyrepo/PayloadsAllTheThings/SQL injection
[Link]
[Link]